PatchSiren

wpvibes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wpvibes CVE published 2026-07-11

CVE-2026-13378

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This vulnerability makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p [truncated]

HIGH WPVibes CVE published 2026-06-11

CVE-2023-33999

CVE-2023-33999 is a high-severity DOM-Based XSS vulnerability in WP Mail Log, a WordPress plugin. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2023-33999). The issue affects WP Mail Log versions from n/a through 1.0.2.