PatchSiren

WPPOOL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPPOOL CVE published 2026-07-13

CVE-2026-57379

CVE-2026-57379 is a Stored XSS vulnerability in FormyChat social-contact-form. The issue affects FormyChat from n/a through <= 2.15.3. The vulnerability has a CVSS score of 7.1 and a HIGH severity rating. The vulnerability is caused by improper neutralization of input during web page generation, allowing for Stored XSS attacks. Users of FormyChat social-contact-form, especially those with versions <= 2.15 [truncated]

MEDIUM WPPOOL CVE published 2026-05-25

CVE-2026-24582

A Missing Authorization vulnerability in the WPPOOL FlexTable WordPress plugin allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions from n/a through 3.24.0. The issue was published to the CVE List on 2026-05-25 and last modified on 2026-05-26. The NVD entry currently shows a status of 'Deferred'.