PatchSiren

zookatron CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM zookatron CVE published 2026-04-08

CVE-2026-39604

CVE-2026-39604 is a Stored Cross-site Scripting (XSS) vulnerability in the MyBookTable Bookstore plugin for WordPress. This issue, affecting versions from n/a through 3.6.0, allows an attacker to inject malicious scripts into web pages, potentially leading to unauthorized actions or data exposure. Users of the MyBookTable Bookstore plugin should review and update their installations to mitigate this risk.