PatchSiren

WPZOOM CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPZOOM CVE published 2026-07-13

CVE-2026-57712

CVE-2026-57712 is a Reflected XSS vulnerability in WPZOOM Portfolio, a WordPress plugin. The vulnerability affects WPZOOM Portfolio from n/a through <= 1.4.29. This issue has a CVSS score of 7.1 and a CVSS severity of HIGH. The vulnerability is caused by improper neutralization of input during web page generation, allowing for Reflected XSS attacks. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/ [truncated]

HIGH WPZOOM CVE published 2026-06-17

CVE-2026-39597

CVE-2026-39597 is a HIGH-severity vulnerability in WPZOOM Addons for Elementor plugin versions <= 1.3.4. It allows unauthenticated Cross Site Scripting (XSS) attacks. The vulnerability was published on June 17, 2026, and has a CVSS score of 7.1. Users of affected versions should update to a patched version immediately. The vulnerability was reported by Patchstack. No ransomware campaigns have been linked [truncated]

HIGH WPZOOM CVE published 2026-06-10

CVE-2026-49069

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WPZOOM Portfolio plugin. This issue, tracked as CVE-2026-49069, allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity.

MEDIUM wpzoom CVE published 2026-06-08

CVE-2026-3011

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for auth [truncated]