{
  "ruleset": "codelake-wp-vuln-rules",
  "generated": "2026-08-03T08:37:28Z",
  "source": "codelake Research — confirmed WordPress plugin vulnerabilities: public CVE/NVD plus codelake's own SAST.",
  "license": "Proprietary — © codelake Research. Licensed for use within codelake / BlockForge products only. Not for redistribution.",
  "notice": "Every rule is a CONFIRMED (corroborated) vulnerability at an exact scanned plugin version. affected_versions lists the versions we verified; for CVE-sourced rules consult the CVE for the full affected range. No exploit file/line locations are included.",
  "rule_count": 2013,
  "rules": [
    {
      "id": "CLR-WP-12-STEP-MEETING-LIST-XSS-CVE-2025-24748",
      "plugin_slug": "12-step-meeting-list",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24748",
      "affected_versions": [
        "3.19.15"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24748",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-247TRADEMATE-CHAT-ASSISTANT-XSS-CWE-79",
      "plugin_slug": "247trademate-chat-assistant",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.28",
        "1.1.64",
        "1.1.77"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-24TT-DOCUMENT-VERIFIER-XSS-CWE-79",
      "plugin_slug": "24tt-document-verifier",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-301-REDIRECTS-CSRF-CVE-2019-19915",
      "plugin_slug": "301-redirects",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "critical",
      "cve": "CVE-2019-19915",
      "affected_versions": [
        "1.05"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-19915",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-301-REDIRECTS-SQLI-CVE-2021-24142",
      "plugin_slug": "301-redirects",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2021-24142",
      "affected_versions": [
        "1.05"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24142",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3D-VIEWER-KNOWN-CVE-CVE-2021-43209",
      "plugin_slug": "3d-viewer",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2021-43209",
      "affected_versions": [
        "1.8.13",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-43209",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3D-VIEWER-KNOWN-CVE-CVE-2023-36739",
      "plugin_slug": "3d-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-122",
      "severity": "high",
      "cve": "CVE-2023-36739",
      "affected_versions": [
        "1.8.13",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-36739",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3D-VIEWER-KNOWN-CVE-CVE-2023-36740",
      "plugin_slug": "3d-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-122",
      "severity": "high",
      "cve": "CVE-2023-36740",
      "affected_versions": [
        "1.8.13",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-36740",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3D-VIEWER-KNOWN-CVE-CVE-2023-36760",
      "plugin_slug": "3d-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-416",
      "severity": "high",
      "cve": "CVE-2023-36760",
      "affected_versions": [
        "1.8.13",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-36760",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3D-VIEWER-RCE-CVE-2021-43208",
      "plugin_slug": "3d-viewer",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "high",
      "cve": "CVE-2021-43208",
      "affected_versions": [
        "1.8.13",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-43208",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-3DPRINT-LITE-XSS-CVE-2025-30897",
      "plugin_slug": "3dprint-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-30897",
      "affected_versions": [
        "2.1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30897",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-404ZEN-BROKEN-LINK-FIXER-XSS-CWE-79",
      "plugin_slug": "404zen-broken-link-fixer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2",
        "1.1.0",
        "1.1.1",
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 85,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-5CENTSCDN-XSS-CWE-79",
      "plugin_slug": "5centscdn",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "26.06.09"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-90-IN-90-XSS-CWE-79",
      "plugin_slug": "90-in-90",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ACADEMY-RCE-CVE-2025-62149",
      "plugin_slug": "academy",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2025-62149",
      "affected_versions": [
        "3.8.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62149",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ACADEMY-RCE-CVE-2025-62149",
      "plugin_slug": "academy",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "cve": "CVE-2025-62149",
      "affected_versions": [
        "3.8.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62149",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-ACCEPT-STRIPE-FOR-CONTACT-FORM-7-XSS-CWE-79",
      "plugin_slug": "accept-stripe-for-contact-form-7",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-ACE-USER-MANAGEMENT-SSRF-CWE-918",
      "plugin_slug": "ace-user-management",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ACE-USER-MANAGEMENT-SSRF-CWE-918",
      "plugin_slug": "ace-user-management",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ACF-FRONTEND-FORM-ELEMENT-XSS-CVE-2024-10783",
      "plugin_slug": "acf-frontend-form-element",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-10783",
      "affected_versions": [
        "3.29.5",
        "3.29.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 51,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ACTIVECAMPAIGN-SUBSCRIPTION-FORMS-XSS-CWE-79",
      "plugin_slug": "activecampaign-subscription-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.1.21"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ACTIVITYPUB-XSS-CWE-79",
      "plugin_slug": "activitypub",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.2",
        "9.1.0",
        "9.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AD-FUZ-XSS-CWE-79",
      "plugin_slug": "ad-fuz",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.1",
        "1.1.10",
        "1.1.12",
        "1.1.13",
        "1.1.14",
        "1.1.2",
        "1.1.3",
        "1.1.4",
        "1.1.5",
        "1.1.6",
        "1.1.7",
        "1.1.8",
        "1.2.1",
        "1.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 113,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AD-INSERTER-XSS-CVE-2026-48869",
      "plugin_slug": "ad-inserter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-48869",
      "affected_versions": [
        "2.8.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-48869",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADD-EXPIRES-HEADERS-XSS-CWE-79",
      "plugin_slug": "add-expires-headers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADD-FIELDS-TO-CHECKOUT-PAGE-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "add-fields-to-checkout-page-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADD-SEARCH-TO-MENU-XSS-CWE-79",
      "plugin_slug": "add-search-to-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.5.16"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADD-TO-FEEDLY-XSS-CVE-2025-58855",
      "plugin_slug": "add-to-feedly",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58855",
      "affected_versions": [
        "1.2.11"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58855",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADD-TO-FEEDLY-XSS-CVE-2025-58855",
      "plugin_slug": "add-to-feedly",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-58855",
      "affected_versions": [
        "1.2.11"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58855",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADMIN-NOTE-SQLI-CWE-89",
      "plugin_slug": "admin-note",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADMIN-NOTE-SQLI-CWE-89",
      "plugin_slug": "admin-note",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADMIN-NOTE-XSS-CWE-79",
      "plugin_slug": "admin-note",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADMIN-USER-CONTROL-XSS-CWE-79",
      "plugin_slug": "admin-user-control",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ADMINISTRATOR-Z-XSS-CWE-79",
      "plugin_slug": "administrator-z",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2026.06.03"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCE-MENU-MANAGER-XSS-CVE-2024-11709",
      "plugin_slug": "advance-menu-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11709",
      "affected_versions": [
        "3.1.3",
        "3.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 55,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11709",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCE-WC-ANALYTICS-XSS-CWE-79",
      "plugin_slug": "advance-wc-analytics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCED-301-AND-302-REDIRECT-SQLI-CWE-89",
      "plugin_slug": "advanced-301-and-302-redirect",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-ADVANCED-301-AND-302-REDIRECT-SQLI-CWE-89",
      "plugin_slug": "advanced-301-and-302-redirect",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.7.0",
        "1.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ADVANCED-CF7-DB-XSS-CVE-2025-1794",
      "plugin_slug": "advanced-cf7-db",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1794",
      "affected_versions": [
        "2.1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1794",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCED-CLASSIFIEDS-AND-DIRECTORY-PRO-XSS-CWE-79",
      "plugin_slug": "advanced-classifieds-and-directory-pro",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.2",
        "3.4.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 74,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCED-COUPONS-FOR-WOOCOMMERCE-FREE-XSS-CWE-79",
      "plugin_slug": "advanced-coupons-for-woocommerce-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.7.3",
        "4.7.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ADVANCED-CUSTOM-CSS-XSS-CVE-2025-68891",
      "plugin_slug": "advanced-custom-css",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68891",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68891",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCED-CUSTOM-FIELDS-XSS-CWE-79",
      "plugin_slug": "advanced-custom-fields",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.8.5",
        "6.8.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADVANCED-DYNAMIC-PRICING-FOR-WOOCOMMERCE-SQLI-CVE-2025-39465",
      "plugin_slug": "advanced-dynamic-pricing-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-39465",
      "affected_versions": [
        "4.13.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39465",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ADVANCED-DYNAMIC-PRICING-FOR-WOOCOMMERCE-SQLI-CVE-2025-39465",
      "plugin_slug": "advanced-dynamic-pricing-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-39465",
      "affected_versions": [
        "4.13.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39465",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ADVANCED-FLOATING-CONTENT-LITE-XSS-CWE-79",
      "plugin_slug": "advanced-floating-content-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-ADVANCED-IFRAME-XSS-CWE-79",
      "plugin_slug": "advanced-iframe",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2026.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ADVANCED-SERMONS-XSS-CWE-79",
      "plugin_slug": "advanced-sermons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ADZ-WORLD-SQLI-CWE-89",
      "plugin_slug": "adz-world",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ADZ-WORLD-SQLI-CWE-89",
      "plugin_slug": "adz-world",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ADZ-WORLD-XSS-CWE-79",
      "plugin_slug": "adz-world",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AEROSCROLL-GALLERY-SQLI-CVE-2025-49864",
      "plugin_slug": "aeroscroll-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-49864",
      "affected_versions": [
        "1.0.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49864",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AEROSCROLL-GALLERY-SQLI-CVE-2025-49864",
      "plugin_slug": "aeroscroll-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-49864",
      "affected_versions": [
        "1.0.13"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49864",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AF-COMPANION-XSS-CWE-79",
      "plugin_slug": "af-companion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AF-TRANSLATE-XSS-CWE-79",
      "plugin_slug": "af-translate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.0",
        "3.1.1",
        "3.1.2",
        "4.0.0",
        "4.0.1",
        "4.0.2",
        "4.0.3",
        "4.0.4",
        "5.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 79,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AGENTICDAISY-CALENDAR-XSS-CWE-79",
      "plugin_slug": "agenticdaisy-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.4",
        "1.1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-AGILE-STORE-LOCATOR-SQLI-CVE-2025-14293",
      "plugin_slug": "agile-store-locator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-14293",
      "affected_versions": [
        "1.6.11",
        "1.6.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14293",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AGILE-STORE-LOCATOR-SQLI-CVE-2025-14293",
      "plugin_slug": "agile-store-locator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-14293",
      "affected_versions": [
        "1.6.11",
        "1.6.13"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 80,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14293",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AI-DOS-CVE-2026-8769",
      "plugin_slug": "ai",
      "vuln_class": "dos",
      "cwe": "CWE-400",
      "severity": "medium",
      "cve": "CVE-2026-8769",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-8769",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-KNOWN-CVE-CVE-2025-48985",
      "plugin_slug": "ai",
      "vuln_class": "known-cve",
      "cwe": "CWE-20",
      "severity": "low",
      "cve": "CVE-2025-48985",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48985",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-KNOWN-CVE-CVE-2026-12057",
      "plugin_slug": "ai",
      "vuln_class": "known-cve",
      "cwe": "CWE-829",
      "severity": "high",
      "cve": "CVE-2026-12057",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-12057",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-RCE-CVE-2026-8767",
      "plugin_slug": "ai",
      "vuln_class": "rce",
      "cwe": "CWE-77",
      "severity": "medium",
      "cve": "CVE-2026-8767",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-8767",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-SSRF-CVE-2026-8768",
      "plugin_slug": "ai",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-8768",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-8768",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-SSRF-CVE-2024-23654",
      "plugin_slug": "ai",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2024-23654",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-23654",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-AUTO-TOOL-SSRF-CVE-2025-64262",
      "plugin_slug": "ai-auto-tool",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-64262",
      "affected_versions": [
        "2.3.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-64262",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AI-AUTO-TOOL-SSRF-CVE-2025-64262",
      "plugin_slug": "ai-auto-tool",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-64262",
      "affected_versions": [
        "2.3.9"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-64262",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AI-ENGINE-FILE-UPLOAD-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-FILE-UPLOAD-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "medium",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-KNOWN-CVE-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-KNOWN-CVE-CVE-2025-4406",
      "plugin_slug": "ai-engine",
      "vuln_class": "known-cve",
      "cwe": "CWE-532",
      "severity": "high",
      "cve": "CVE-2025-4406",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4406",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-AI-ENGINE-KNOWN-CVE-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "known-cve",
      "cwe": "CWE-532",
      "severity": "high",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SQLI-CVE-2025-4406",
      "plugin_slug": "ai-engine",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-4406",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4406",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SQLI-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SQLI-CVE-2025-4406",
      "plugin_slug": "ai-engine",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2025-4406",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4406",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SQLI-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SSRF-CVE-2025-4406",
      "plugin_slug": "ai-engine",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-4406",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4406",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-AI-ENGINE-SSRF-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-ENGINE-XSS-CVE-2025-4406",
      "plugin_slug": "ai-engine",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-4406",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4406",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-AI-ENGINE-XSS-CVE-2025-67978",
      "plugin_slug": "ai-engine",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-67978",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67978",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-LOG-ANALYZER-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "ai-log-analyzer-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-AI-TEXT-TO-SPEECH-XSS-CWE-79",
      "plugin_slug": "ai-text-to-speech",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AI-TRANSLATE-XSS-CWE-79",
      "plugin_slug": "ai-translate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-AI-WP-WRITER-SQLI-CWE-89",
      "plugin_slug": "ai-wp-writer",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.6.1.1",
        "4.6.2.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AI-WP-WRITER-SQLI-CWE-89",
      "plugin_slug": "ai-wp-writer",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.6.1.1",
        "4.6.2.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AIRDROP-KNOWN-CVE-CVE-2019-9832",
      "plugin_slug": "airdrop",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2019-9832",
      "affected_versions": [
        "1.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-9832",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AIRWALLEX-ONLINE-PAYMENTS-GATEWAY-XSS-CWE-79",
      "plugin_slug": "airwallex-online-payments-gateway",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.34.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AJAR-PRODUCTIONS-IN5-EMBED-XSS-CWE-79",
      "plugin_slug": "ajar-productions-in5-embed",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AJAX-SEARCH-LITE-XSS-CWE-79",
      "plugin_slug": "ajax-search-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.14.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ALAMIN-VENDOR-TASKS-DOKAN-CLICKUP-XSS-CWE-79",
      "plugin_slug": "alamin-vendor-tasks-dokan-clickup",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ALL-EMBED-ADDONS-FOR-ELEMENTOR-XSS-CVE-2024-12512",
      "plugin_slug": "all-embed-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12512",
      "affected_versions": [
        "1.1.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12512",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ALL-IN-ONE-PERFORMANCE-ACCELERATOR-SQLI-CVE-2025-22669",
      "plugin_slug": "all-in-one-performance-accelerator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-22669",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22669",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ALL-IN-ONE-PERFORMANCE-ACCELERATOR-SQLI-CVE-2025-22669",
      "plugin_slug": "all-in-one-performance-accelerator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-22669",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22669",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ALL-IN-ONE-VIDEO-GALLERY-XSS-CWE-79",
      "plugin_slug": "all-in-one-video-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ALL-IN-ONE-WP-MIGRATION-XSS-CWE-79",
      "plugin_slug": "all-in-one-wp-migration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.106",
        "7.107"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ALLDAR-LEAD-SYNC-XSS-CWE-79",
      "plugin_slug": "alldar-lead-sync",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-ALLPOST-CONTACTFORM-XSS-CWE-79",
      "plugin_slug": "allpost-contactform",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-AMAZONSIMPLEADMIN-XSS-CVE-2026-6169",
      "plugin_slug": "amazonsimpleadmin",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-6169",
      "affected_versions": [
        "1.10.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-6169",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AMBERLINK-XSS-CVE-2025-23880",
      "plugin_slug": "amberlink",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-23880",
      "affected_versions": [
        "1.4.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-23880",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AMCHARTS-CHARTS-AND-MAPS-XSS-CWE-79",
      "plugin_slug": "amcharts-charts-and-maps",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ANDROAPP-XSS-CWE-79",
      "plugin_slug": "androapp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "25.03"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ANIMATED-FULLSCREEN-MENU-XSS-CWE-79",
      "plugin_slug": "animated-fullscreen-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ANNOUNCEMENT-BAR-XSS-CWE-79",
      "plugin_slug": "announcement-bar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ANTI-HACKER-BROKEN-ACCESS-CONTROL-CVE-2024-1860",
      "plugin_slug": "anti-hacker",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2024-1860",
      "affected_versions": [
        "0.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-1860",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTI-HACKER-BROKEN-ACCESS-CONTROL-CVE-2024-1861",
      "plugin_slug": "anti-hacker",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2024-1861",
      "affected_versions": [
        "0.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-1861",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTI-HACKER-CSRF-CVE-2023-50858",
      "plugin_slug": "anti-hacker",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2023-50858",
      "affected_versions": [
        "0.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-50858",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2017-8307",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "severity": "critical",
      "cve": "CVE-2017-8307",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2017-8307",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2009-1431",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2009-1431",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1431",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2016-10402",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "cwe": "CWE-119",
      "severity": "high",
      "cve": "CVE-2016-10402",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2016-10402",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2009-1430",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "cwe": "CWE-119",
      "severity": "medium",
      "cve": "CVE-2009-1430",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1430",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2017-8308",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "cwe": "CWE-269",
      "severity": "high",
      "cve": "CVE-2017-8308",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2017-8308",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-KNOWN-CVE-CVE-2009-3482",
      "plugin_slug": "antivirus",
      "vuln_class": "known-cve",
      "cwe": "CWE-732",
      "severity": "high",
      "cve": "CVE-2009-3482",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-3482",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-RCE-CVE-2009-1429",
      "plugin_slug": "antivirus",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2009-1429",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1429",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTIVIRUS-XSS-CVE-2009-1428",
      "plugin_slug": "antivirus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2009-1428",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1428",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ANTRADUS-AI-LITE-XSS-CWE-79",
      "plugin_slug": "antradus-ai-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-ANYTRY-AI-VIRTUAL-TRY-ON-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "anytry-ai-virtual-try-on-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.21"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-APEX-DIGITAL-TOOLBOX-XSS-CWE-79",
      "plugin_slug": "apex-digital-toolbox",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-30"
    },
    {
      "id": "CLR-WP-APM-CHILD-SQLI-CWE-89",
      "plugin_slug": "apm-child",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-APM-CHILD-SQLI-CWE-89",
      "plugin_slug": "apm-child",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-APOCALYPSE-MEOW-SQLI-CWE-89",
      "plugin_slug": "apocalypse-meow",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "23.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APOCALYPSE-MEOW-SQLI-CWE-89",
      "plugin_slug": "apocalypse-meow",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "23.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APPGRADE-NAUTICA-XSS-CWE-79",
      "plugin_slug": "appgrade-nautica",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-APPLY-ONLINE-XSS-CVE-2024-12767",
      "plugin_slug": "apply-online",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12767",
      "affected_versions": [
        "2.6.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12767",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APPOINTMENT-BOOKING-CALENDAR-XSS-CVE-2025-46489",
      "plugin_slug": "appointment-booking-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-46489",
      "affected_versions": [
        "1.4.04"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46489",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APPOINTMENT-BOOKING-CALENDAR-XSS-CVE-2025-46489",
      "plugin_slug": "appointment-booking-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-46489",
      "affected_versions": [
        "1.4.04"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46489",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APPOINTMENT-RESERVATION-AND-RENTAL-BOOKING-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "appointment-reservation-and-rental-booking-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-APPPRESSER-XSS-CVE-2024-11103",
      "plugin_slug": "apppresser",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11103",
      "affected_versions": [
        "4.5.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11103",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-APPTEN-IMAGE-ROTATOR-XSS-CWE-79",
      "plugin_slug": "appten-image-rotator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-APTIVADA-FOR-WP-XSS-CVE-2025-48135",
      "plugin_slug": "aptivada-for-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-48135",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48135",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AR-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "ar-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.42",
        "8.43",
        "8.44",
        "8.45"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AR-FOR-WORDPRESS-XSS-CWE-79",
      "plugin_slug": "ar-for-wordpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.42",
        "8.43",
        "8.44",
        "8.45"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ARTIFICIAL-INTELLIGENCE-AUTO-CONTENT-GENERATOR-XSS-CWE-79",
      "plugin_slug": "artificial-intelligence-auto-content-generator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ASAFFILI-SQLI-CWE-89",
      "plugin_slug": "asaffili",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 25,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ASAFFILI-SQLI-CWE-89",
      "plugin_slug": "asaffili",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ASSISTANT-KNOWN-CVE-CVE-2025-0817",
      "plugin_slug": "assistant",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2025-0817",
      "affected_versions": [
        "1.5.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0817",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ASSISTANT-KNOWN-CVE-CVE-2025-0817",
      "plugin_slug": "assistant",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-0817",
      "affected_versions": [
        "1.5.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0817",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ASSISTANT-KNOWN-CVE-CVE-2025-0817",
      "plugin_slug": "assistant",
      "vuln_class": "known-cve",
      "cwe": "CWE-276",
      "severity": "medium",
      "cve": "CVE-2025-0817",
      "affected_versions": [
        "1.5.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0817",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ASSISTANT-KNOWN-CVE-CVE-2025-0817",
      "plugin_slug": "assistant",
      "vuln_class": "known-cve",
      "cwe": "CWE-346",
      "severity": "medium",
      "cve": "CVE-2025-0817",
      "affected_versions": [
        "1.5.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0817",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ASSISTANT-KNOWN-CVE-CVE-2025-0817",
      "plugin_slug": "assistant",
      "vuln_class": "known-cve",
      "cwe": "CWE-426",
      "severity": "high",
      "cve": "CVE-2025-0817",
      "affected_versions": [
        "1.5.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0817",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ATHEMES-STARTER-SITES-SSRF-CWE-918",
      "plugin_slug": "athemes-starter-sites",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.3.1",
        "1.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ATHEMES-STARTER-SITES-SSRF-CWE-918",
      "plugin_slug": "athemes-starter-sites",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.3.1",
        "1.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ATT-YOUTUBE-XSS-CVE-2025-52755",
      "plugin_slug": "att-youtube",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-52755",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-52755",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ATUM-STOCK-MANAGER-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "atum-stock-manager-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.2",
        "2.0.3",
        "2.0.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-AUCTION-FEED-XSS-CVE-2025-57983",
      "plugin_slug": "auction-feed",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-57983",
      "affected_versions": [
        "1.1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57983",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUSTRALCODE-DTE-STOCK-SYNC-BSALE-XSS-CWE-79",
      "plugin_slug": "australcode-dte-stock-sync-bsale",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.7.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-AUTHOR-AVATARS-XSS-CWE-79",
      "plugin_slug": "author-avatars",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.26"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTO-INSTALL-FREE-SSL-XSS-CWE-79",
      "plugin_slug": "auto-install-free-ssl",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.6.3",
        "4.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 67,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTO-LISTINGS-SQLI-CWE-89",
      "plugin_slug": "auto-listings",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.7.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTO-LISTINGS-SQLI-CWE-89",
      "plugin_slug": "auto-listings",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.7.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTO-ROBOT-XSS-CWE-79",
      "plugin_slug": "auto-robot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.74",
        "4.0.75",
        "4.0.76",
        "4.0.78",
        "4.0.79"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 88,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTOGLOT-XSS-CWE-79",
      "plugin_slug": "autoglot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.11.10",
        "2.11.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-AUTOMATIC-BAN-IP-SQLI-CVE-2025-32604",
      "plugin_slug": "automatic-ban-ip",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-32604",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32604",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTOMATIC-BAN-IP-XSS-CVE-2025-32604",
      "plugin_slug": "automatic-ban-ip",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32604",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 46,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32604",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTOMATIC-POST-TAGGER-XSS-CWE-79",
      "plugin_slug": "automatic-post-tagger",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTOMATORWP-XSS-CVE-2025-58922",
      "plugin_slug": "automatorwp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58922",
      "affected_versions": [
        "5.7.9.2",
        "5.8.0",
        "5.8.1",
        "5.8.2",
        "5.8.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58922",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTOMATTIC-FOR-AGENCIES-CLIENT-SSRF-CWE-918",
      "plugin_slug": "automattic-for-agencies-client",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "0.8.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTOMATTIC-FOR-AGENCIES-CLIENT-SSRF-CWE-918",
      "plugin_slug": "automattic-for-agencies-client",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "0.8.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AUTOMOTIVE-FEED-IMPORT-XSS-CWE-79",
      "plugin_slug": "automotive-feed-import",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-AUTOPTIMIZE-XSS-CWE-79",
      "plugin_slug": "autoptimize",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.15.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUTOSHIP-CLOUD-XSS-CVE-2025-69103",
      "plugin_slug": "autoship-cloud",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69103",
      "affected_versions": [
        "2.14.4",
        "2.15.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69103",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AUXIN-ELEMENTS-XSS-CWE-79",
      "plugin_slug": "auxin-elements",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.17.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-AUXIN-ELEMENTS-XSS-CVE-2024-11902",
      "plugin_slug": "auxin-elements",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11902",
      "affected_versions": [
        "2.17.21"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11902",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AVALON23-PRODUCTS-FILTER-FOR-WOOCOMMERCE-SQLI-CVE-2025-68075",
      "plugin_slug": "avalon23-products-filter-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-68075",
      "affected_versions": [
        "1.1.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68075",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AVALON23-PRODUCTS-FILTER-FOR-WOOCOMMERCE-SQLI-CVE-2025-68075",
      "plugin_slug": "avalon23-products-filter-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-68075",
      "affected_versions": [
        "1.1.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68075",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AWCODE-TOOLKIT-XSS-CVE-2025-31054",
      "plugin_slug": "awcode-toolkit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31054",
      "affected_versions": [
        "1.0.24"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31054",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AWESOME-EVENT-BOOKING-XSS-CVE-2024-11133",
      "plugin_slug": "awesome-event-booking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11133",
      "affected_versions": [
        "2.8.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11133",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-AWESOME-POSTS-XSS-CWE-79",
      "plugin_slug": "awesome-posts",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AWESOME-TEAM-WIDGETS-XSS-CWE-79",
      "plugin_slug": "awesome-team-widgets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AWESOME-WIDGETS-XSS-CWE-79",
      "plugin_slug": "awesome-widgets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-AYS-CHATGPT-ASSISTANT-XSS-CVE-2025-22657",
      "plugin_slug": "ays-chatgpt-assistant",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22657",
      "affected_versions": [
        "2.8.2",
        "2.8.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22657",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-B1-ACCOUNTING-XSS-CWE-79",
      "plugin_slug": "b1-accounting",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.72"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BA-BOOK-EVERYTHING-XSS-CVE-2026-22481",
      "plugin_slug": "ba-book-everything",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-22481",
      "affected_versions": [
        "1.8.25",
        "1.8.26"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 40,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-22481",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BACK-IN-STOCK-NOTIFIER-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "back-in-stock-notifier-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.2.2",
        "7.3.0",
        "7.3.1",
        "7.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BACKUP-KNOWN-CVE-CVE-2014-9633",
      "plugin_slug": "backup",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "medium",
      "cve": "CVE-2014-9633",
      "affected_versions": [
        "3.1.22.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2014-9633",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BACKUP-KNOWN-CVE-CVE-2019-15720",
      "plugin_slug": "backup",
      "vuln_class": "known-cve",
      "cwe": "CWE-269",
      "severity": "high",
      "cve": "CVE-2019-15720",
      "affected_versions": [
        "3.1.22.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-15720",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BACKUP-SQLI-CVE-2018-6329",
      "plugin_slug": "backup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2018-6329",
      "affected_versions": [
        "3.1.22.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2018-6329",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BACKUP-SQLI-CVE-2020-8427",
      "plugin_slug": "backup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2020-8427",
      "affected_versions": [
        "3.1.22.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2020-8427",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BACKUPLY-SSRF-CVE-2025-57976",
      "plugin_slug": "backuply",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-57976",
      "affected_versions": [
        "1.5.3",
        "1.5.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57976",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BACKUPLY-SSRF-CVE-2025-57976",
      "plugin_slug": "backuply",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-57976",
      "affected_versions": [
        "1.5.3",
        "1.5.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57976",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BACKUPRIDGE-XSS-CWE-79",
      "plugin_slug": "backupridge",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.29.0",
        "1.29.1",
        "1.29.3",
        "1.30.0",
        "1.30.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BADGE-XSS-CVE-2022-23108",
      "plugin_slug": "badge",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-23108",
      "affected_versions": [
        "1.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-23108",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BANNER-MANAGEMENT-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "banner-management-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BARCODE-SCANNER-LITE-POS-TO-MANAGE-PRODUCTS-INVENTORY-AND-ORDERS-SQLI-CVE-2025-8081",
      "plugin_slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-8081",
      "affected_versions": [
        "1.13.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8081",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BARCODE-SCANNER-LITE-POS-TO-MANAGE-PRODUCTS-INVENTORY-AND-ORDERS-SQLI-CVE-2025-8081",
      "plugin_slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-8081",
      "affected_versions": [
        "1.13.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8081",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BARCODE-SCANNER-LITE-POS-TO-MANAGE-PRODUCTS-INVENTORY-AND-ORDERS-XSS-CVE-2025-8081",
      "plugin_slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8081",
      "affected_versions": [
        "1.13.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8081",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BASEPRESS-XSS-CVE-2025-14387",
      "plugin_slug": "basepress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-14387",
      "affected_versions": [
        "2.17.0.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14387",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BBP-MOVE-TOPICS-XSS-CVE-2025-49962",
      "plugin_slug": "bbp-move-topics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49962",
      "affected_versions": [
        "1.1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49962",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BBP-STYLE-PACK-XSS-CWE-79",
      "plugin_slug": "bbp-style-pack",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.4.6",
        "6.4.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 83,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BCM-DUPLICATE-MENU-XSS-CVE-2025-58594",
      "plugin_slug": "bcm-duplicate-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58594",
      "affected_versions": [
        "1.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58594",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BETTER-WLM-API-XSS-CVE-2024-13377",
      "plugin_slug": "better-wlm-api",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13377",
      "affected_versions": [
        "1.1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13377",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BEYONDCART-XSS-CWE-79",
      "plugin_slug": "beyondcart",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BEYONDSEO-SSRF-CWE-918",
      "plugin_slug": "beyondseo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.2.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-BEYONDSEO-SSRF-CWE-918",
      "plugin_slug": "beyondseo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.2.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-BFT-AUTORESPONDER-SQLI-CVE-2025-39446",
      "plugin_slug": "bft-autoresponder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-39446",
      "affected_versions": [
        "2.7.2.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39446",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BFT-AUTORESPONDER-SQLI-CVE-2025-39446",
      "plugin_slug": "bft-autoresponder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-39446",
      "affected_versions": [
        "2.7.2.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39446",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BFT-AUTORESPONDER-XSS-CVE-2025-39446",
      "plugin_slug": "bft-autoresponder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39446",
      "affected_versions": [
        "2.7.2.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39446",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BINA-CF7-XSS-CWE-79",
      "plugin_slug": "bina-cf7",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-26"
    },
    {
      "id": "CLR-WP-BIT-FORM-BROKEN-ACCESS-CONTROL-CVE-2025-39370",
      "plugin_slug": "bit-form",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "high",
      "cve": "CVE-2025-39370",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BIT-FORM-FILE-UPLOAD-CVE-2025-39370",
      "plugin_slug": "bit-form",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2025-39370",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BIT-FORM-KNOWN-CVE-CVE-2025-39370",
      "plugin_slug": "bit-form",
      "vuln_class": "known-cve",
      "severity": "critical",
      "cve": "CVE-2025-39370",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BIT-FORM-KNOWN-CVE-CVE-2025-39370",
      "plugin_slug": "bit-form",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-39370",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BIT-FORM-LFI-CVE-2025-39370",
      "plugin_slug": "bit-form",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "high",
      "cve": "CVE-2025-39370",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BITFIRE-SSRF-CWE-918",
      "plugin_slug": "bitfire",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "5.0.9",
        "5.1.0",
        "5.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BITFIRE-SSRF-CWE-918",
      "plugin_slug": "bitfire",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "5.0.9",
        "5.1.0",
        "5.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BITFIRE-XSS-CWE-79",
      "plugin_slug": "bitfire",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.0.9",
        "5.1.0",
        "5.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLACK-DESK-SQLI-CWE-89",
      "plugin_slug": "black-desk",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.8.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-BLACK-DESK-SQLI-CWE-89",
      "plugin_slug": "black-desk",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.8.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-BLAZE-ONLINE-EPARCEL-FOR-WOOCOMMERCE-SQLI-CVE-2024-54208",
      "plugin_slug": "blaze-online-eparcel-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-54208",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54208",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLAZE-ONLINE-EPARCEL-FOR-WOOCOMMERCE-XSS-CVE-2024-54208",
      "plugin_slug": "blaze-online-eparcel-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54208",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54208",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLOCK-CONTROLLER-XSS-CVE-2024-54238",
      "plugin_slug": "block-controller",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54238",
      "affected_versions": [
        "1.4.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54238",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLOCK-FOR-MAILCHIMP-XSS-CVE-2026-57630",
      "plugin_slug": "block-for-mailchimp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-57630",
      "affected_versions": [
        "1.1.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57630",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLOCK-SLIDER-XSS-CVE-2025-14943",
      "plugin_slug": "block-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-14943",
      "affected_versions": [
        "2.2.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14943",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BLOCKONS-XSS-CVE-2026-25451",
      "plugin_slug": "blockons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25451",
      "affected_versions": [
        "1.2.19"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25451",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLOCKSPARE-XSS-CVE-2025-47488",
      "plugin_slug": "blockspare",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47488",
      "affected_versions": [
        "4.2.1",
        "4.2.2",
        "4.2.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47488",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BLOCKSY-COMPANION-CSRF-CVE-2026-56007",
      "plugin_slug": "blocksy-companion",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-56007",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56007",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-BLOCKSY-COMPANION-KNOWN-CVE-CVE-2026-56007",
      "plugin_slug": "blocksy-companion",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2026-56007",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56007",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-BLOCKSY-COMPANION-SSRF-CVE-2026-56007",
      "plugin_slug": "blocksy-companion",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-56007",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56007",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-BLOCKSY-COMPANION-XSS-CVE-2026-56007",
      "plugin_slug": "blocksy-companion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-56007",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56007",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-BLOCKWHEELS-XSS-CVE-2025-31759",
      "plugin_slug": "blockwheels",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31759",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31759",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BLOG-DESIGNER-PACK-XSS-CWE-79",
      "plugin_slug": "blog-designer-pack",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BLOG-VOYEUR-SQLI-CWE-89",
      "plugin_slug": "blog-voyeur",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BLOG-VOYEUR-SQLI-CWE-89",
      "plugin_slug": "blog-voyeur",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BLOG-VOYEUR-XSS-CWE-79",
      "plugin_slug": "blog-voyeur",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BLOG2SOCIAL-SQLI-CWE-89",
      "plugin_slug": "blog2social",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "9.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BLOG2SOCIAL-XSS-CWE-79",
      "plugin_slug": "blog2social",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 57,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BLOGIBOT-XSS-CWE-79",
      "plugin_slug": "blogibot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BOARD-DOCUMENT-MANAGER-FROM-CHUHPL-SQLI-CVE-2024-11379",
      "plugin_slug": "board-document-manager-from-chuhpl",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-11379",
      "affected_versions": [
        "1.9.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11379",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BOARD-DOCUMENT-MANAGER-FROM-CHUHPL-SQLI-CVE-2024-11379",
      "plugin_slug": "board-document-manager-from-chuhpl",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-11379",
      "affected_versions": [
        "1.9.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11379",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BOARD-DOCUMENT-MANAGER-FROM-CHUHPL-XSS-CVE-2024-11379",
      "plugin_slug": "board-document-manager-from-chuhpl",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11379",
      "affected_versions": [
        "1.9.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11379",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BONUS-FOR-WOO-XSS-CWE-79",
      "plugin_slug": "bonus-for-woo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.2.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-BOOKING-XSS-CWE-79",
      "plugin_slug": "booking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.3",
        "11.4",
        "11.4.1",
        "11.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 51,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-285",
      "severity": "medium",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-CSRF-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-DESERIALIZATION-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-KNOWN-CVE-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-LFI-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "medium",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-SQLI-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-SQLI-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-XSS-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-XSS-CVE-2026-57339",
      "plugin_slug": "booking-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-57339",
      "affected_versions": [
        "3.2.36"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57339",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-CONTACT-FORM-SQLI-CVE-2026-40789",
      "plugin_slug": "booking-calendar-contact-form",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-40789",
      "affected_versions": [
        "1.2.66"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BOOKING-CALENDAR-CONTACT-FORM-XSS-CVE-2026-40789",
      "plugin_slug": "booking-calendar-contact-form",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-40789",
      "affected_versions": [
        "1.2.66"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 33,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BOOKIT-XSS-CVE-2025-66099",
      "plugin_slug": "bookit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-66099",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-66099",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BOSA-ELEMENTOR-FOR-WOOCOMMERCE-SSRF-CWE-918",
      "plugin_slug": "bosa-elementor-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOSA-ELEMENTOR-FOR-WOOCOMMERCE-SSRF-CWE-918",
      "plugin_slug": "bosa-elementor-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BOTBANISH-FIREWALL-CLIENT-XSS-CWE-79",
      "plugin_slug": "botbanish-firewall-client",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.01",
        "9.0.02"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BOTTLE-KNOWN-CVE-CVE-2020-28473",
      "plugin_slug": "bottle",
      "vuln_class": "known-cve",
      "cwe": "CWE-444",
      "severity": "medium",
      "cve": "CVE-2020-28473",
      "affected_versions": [
        "0.3.3",
        "0.3.4",
        "0.3.5",
        "0.3.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2020-28473",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-BOTTLE-KNOWN-CVE-CVE-2022-31799",
      "plugin_slug": "bottle",
      "vuln_class": "known-cve",
      "cwe": "CWE-755",
      "severity": "critical",
      "cve": "CVE-2022-31799",
      "affected_versions": [
        "0.3.3",
        "0.3.4",
        "0.3.5",
        "0.3.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-31799",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-BP-ACTIVITY-PLUS-RELOADED-XSS-CVE-2024-13360",
      "plugin_slug": "bp-activity-plus-reloaded",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13360",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13360",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BP-CLASSIC-XSS-CWE-79",
      "plugin_slug": "bp-classic",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-26"
    },
    {
      "id": "CLR-WP-BP-EMAIL-ASSIGN-TEMPLATES-XSS-CVE-2024-54325",
      "plugin_slug": "bp-email-assign-templates",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54325",
      "affected_versions": [
        "1.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54325",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BP-GROUPBLOG-XSS-CVE-2026-39546",
      "plugin_slug": "bp-groupblog",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39546",
      "affected_versions": [
        "1.9.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39546",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BREAD-BUTTER-XSS-CWE-79",
      "plugin_slug": "bread-butter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.2.0.193",
        "9.3.0.207"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 64,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BREEZE-XSS-CVE-2026-40749",
      "plugin_slug": "breeze",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-40749",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40749",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-BRID-VIDEO-EASY-PUBLISH-XSS-CVE-2024-11829",
      "plugin_slug": "brid-video-easy-publish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11829",
      "affected_versions": [
        "3.8.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 71,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11829",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BRIKPANEL-ADMIN-PANEL-DASHBOARD-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "brikpanel-admin-panel-dashboard-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.1",
        "3.2.10",
        "3.2.12",
        "3.2.15",
        "3.2.17",
        "3.2.19",
        "3.2.21",
        "3.2.22",
        "3.2.23",
        "3.2.27",
        "3.2.3",
        "3.2.30",
        "3.2.4",
        "3.2.5",
        "3.2.6",
        "3.2.7",
        "3.2.8",
        "3.2.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 174,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BROKEN-LINK-CHECKER-SQLI-CVE-2025-49291",
      "plugin_slug": "broken-link-checker",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-49291",
      "affected_versions": [
        "2.4.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49291",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BROKEN-LINK-CHECKER-XSS-CVE-2025-49291",
      "plugin_slug": "broken-link-checker",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49291",
      "affected_versions": [
        "2.4.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49291",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BSD-WOO-STRIPE-CONNECT-SPLIT-PAY-XSS-CWE-79",
      "plugin_slug": "bsd-woo-stripe-connect-split-pay",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8.0",
        "3.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 55,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-BSECURE-XSS-CVE-2025-7437",
      "plugin_slug": "bsecure",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-7437",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-7437",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BSK-GRAVITYFORMS-BLACKLIST-XSS-CWE-79",
      "plugin_slug": "bsk-gravityforms-blacklist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 33,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BUDDYFORMS-BROKEN-ACCESS-CONTROL-CVE-2025-26884",
      "plugin_slug": "buddyforms",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2025-26884",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BUDDYFORMS-BROKEN-ACCESS-CONTROL-CVE-2025-26884",
      "plugin_slug": "buddyforms",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-26884",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BUDDYFORMS-XSS-CVE-2025-26884",
      "plugin_slug": "buddyforms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-26884",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BUDDYPRESS-XSS-CWE-79",
      "plugin_slug": "buddypress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "14.5.0",
        "14.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 49,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BULGARISATION-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "bulgarisation-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.10",
        "4.0.11",
        "4.0.5",
        "4.0.6",
        "4.0.7",
        "4.0.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 39,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BULK-WATERMARK-XSS-CVE-2025-58601",
      "plugin_slug": "bulk-watermark",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58601",
      "affected_versions": [
        "1.6.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58601",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BULLETIN-ANNOUNCEMENTS-RCE-CWE-94",
      "plugin_slug": "bulletin-announcements",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "3.14.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BULLETIN-ANNOUNCEMENTS-RCE-CWE-95",
      "plugin_slug": "bulletin-announcements",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "3.14.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BULLETIN-ANNOUNCEMENTS-XSS-CWE-79",
      "plugin_slug": "bulletin-announcements",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.14.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-BULLETPROOF-CHECKOUT-LITE-XSS-CWE-79",
      "plugin_slug": "bulletproof-checkout-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.26"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-BULLETPROOF-SECURITY-KNOWN-CVE-CVE-2014-8749",
      "plugin_slug": "bulletproof-security",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2014-8749",
      "affected_versions": [
        "7.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2014-8749",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BULLETPROOF-SECURITY-XSS-CWE-79",
      "plugin_slug": "bulletproof-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 35,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BURGEE-XSS-CWE-79",
      "plugin_slug": "burgee",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.4",
        "2.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-BUSINESS-REVIEW-XSS-CWE-79",
      "plugin_slug": "business-review",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-BUSINESSMONITOR-REVIEWFEED-XSS-CWE-79",
      "plugin_slug": "businessmonitor-reviewfeed",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.21"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-BUY-NOW-PAY-LATER-ADDI-XSS-CWE-79",
      "plugin_slug": "buy-now-pay-later-addi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CAB-GRID-XSS-CWE-79",
      "plugin_slug": "cab-grid",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.38"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-CALCULATOR-BUILDER-SQLI-CVE-2024-13656",
      "plugin_slug": "calculator-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-13656",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13656",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALCULATOR-BUILDER-SQLI-CVE-2024-13656",
      "plugin_slug": "calculator-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-13656",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13656",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2022-39915",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "low",
      "cve": "CVE-2022-39915",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-39915",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2017-15891",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "medium",
      "cve": "CVE-2017-15891",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2017-15891",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2022-33705",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-285",
      "severity": "low",
      "cve": "CVE-2022-33705",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-33705",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2023-33183",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-285",
      "severity": "low",
      "cve": "CVE-2023-33183",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-33183",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2018-8927",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "medium",
      "cve": "CVE-2018-8927",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2018-8927",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-BROKEN-ACCESS-CONTROL-CVE-2024-26145",
      "plugin_slug": "calendar",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "medium",
      "cve": "CVE-2024-26145",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-26145",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-CSRF-CVE-2022-22686",
      "plugin_slug": "calendar",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2022-22686",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-22686",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-DOS-CVE-2023-45150",
      "plugin_slug": "calendar",
      "vuln_class": "dos",
      "cwe": "CWE-400",
      "severity": "medium",
      "cve": "CVE-2023-45150",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-45150",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-KNOWN-CVE-CVE-2025-21035",
      "plugin_slug": "calendar",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-21035",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-21035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-KNOWN-CVE-CVE-2023-21464",
      "plugin_slug": "calendar",
      "vuln_class": "known-cve",
      "cwe": "CWE-281",
      "severity": "medium",
      "cve": "CVE-2023-21464",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-21464",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-KNOWN-CVE-CVE-2019-11820",
      "plugin_slug": "calendar",
      "vuln_class": "known-cve",
      "cwe": "CWE-522",
      "severity": "medium",
      "cve": "CVE-2019-11820",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11820",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-KNOWN-CVE-CVE-2022-24838",
      "plugin_slug": "calendar",
      "vuln_class": "known-cve",
      "cwe": "CWE-74",
      "severity": "medium",
      "cve": "CVE-2022-24838",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-24838",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-KNOWN-CVE-CVE-2021-34812",
      "plugin_slug": "calendar",
      "vuln_class": "known-cve",
      "cwe": "CWE-798",
      "severity": "medium",
      "cve": "CVE-2021-34812",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-34812",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-LFI-CVE-2022-27617",
      "plugin_slug": "calendar",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "medium",
      "cve": "CVE-2022-27617",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-27617",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-LFI-CVE-2023-30678",
      "plugin_slug": "calendar",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "medium",
      "cve": "CVE-2023-30678",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-30678",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-LFI-CVE-2018-13299",
      "plugin_slug": "calendar",
      "vuln_class": "lfi",
      "cwe": "CWE-23",
      "severity": "medium",
      "cve": "CVE-2018-13299",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2018-13299",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-RCE-CVE-2019-11829",
      "plugin_slug": "calendar",
      "vuln_class": "rce",
      "cwe": "CWE-78",
      "severity": "high",
      "cve": "CVE-2019-11829",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11829",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2016-10716",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2016-10716",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2016-10716",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2018-3763",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2018-3763",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2018-3763",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2018-8915",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2018-8915",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2018-8915",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2019-11825",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2019-11825",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11825",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2022-22682",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-22682",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-22682",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-XSS-CVE-2026-29052",
      "plugin_slug": "calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-29052",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-29052",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALENDAR-PLUS-SQLI-CWE-89",
      "plugin_slug": "calendar-plus",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CALLIOPE-SOCIAL-PUBLISHER-SSRF-CWE-918",
      "plugin_slug": "calliope-social-publisher",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.4.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-CALLIOPE-SOCIAL-PUBLISHER-SSRF-CWE-918",
      "plugin_slug": "calliope-social-publisher",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.4.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-CAMPAIGN-MONITOR-WP-SQLI-CVE-2024-12257",
      "plugin_slug": "campaign-monitor-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-12257",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12257",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CAMPAIGN-MONITOR-WP-SQLI-CVE-2024-12257",
      "plugin_slug": "campaign-monitor-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-12257",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12257",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CANONICAL-ATTACHMENTS-XSS-CWE-79",
      "plugin_slug": "canonical-attachments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CANTO-SSRF-CVE-2026-39562",
      "plugin_slug": "canto",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "critical",
      "cve": "CVE-2026-39562",
      "affected_versions": [
        "3.1.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39562",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CANTO-SSRF-CVE-2026-39562",
      "plugin_slug": "canto",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-39562",
      "affected_versions": [
        "3.1.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39562",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CANTO-XSS-CVE-2026-39562",
      "plugin_slug": "canto",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39562",
      "affected_versions": [
        "3.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39562",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CAPTAIN-WIDGETS-KIT-SSRF-CWE-918",
      "plugin_slug": "captain-widgets-kit",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CAPTAIN-WIDGETS-KIT-SSRF-CWE-918",
      "plugin_slug": "captain-widgets-kit",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CAPTURE-KNOWN-CVE-CVE-2021-25464",
      "plugin_slug": "capture",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "low",
      "cve": "CVE-2021-25464",
      "affected_versions": [
        "1.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-25464",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CARDEALERPRESS-XSS-CWE-79",
      "plugin_slug": "cardealerpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.0.2606.01"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CAROUSEL-HORIZONTAL-POSTS-CONTENT-SLIDER-XSS-CWE-79",
      "plugin_slug": "carousel-horizontal-posts-content-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CART-TRACKING-FOR-WOOCOMMERCE-XSS-CVE-2025-30765",
      "plugin_slug": "cart-tracking-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-30765",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30765",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CASHBACK-SQLI-CWE-89",
      "plugin_slug": "cashback",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CASHBACK-SQLI-CWE-89",
      "plugin_slug": "cashback",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CASHBACK-XSS-CWE-79",
      "plugin_slug": "cashback",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CATEGORIFY-XSS-CVE-2025-9633",
      "plugin_slug": "categorify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-9633",
      "affected_versions": [
        "1.0.7.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9633",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CATEGORY-POSTS-WIDGET-XSS-CVE-2024-6158",
      "plugin_slug": "category-posts-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-6158",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-6158",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CATEGORY-POSTS-WIDGET-XSS-CVE-2024-9638",
      "plugin_slug": "category-posts-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-9638",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9638",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CATEGORY-POSTS-WIDGET-XSS-CVE-2025-1453",
      "plugin_slug": "category-posts-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-1453",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1453",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CF7-GOOGLE-SHEETS-CONNECTOR-XSS-CWE-79",
      "plugin_slug": "cf7-google-sheets-connector",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.1.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CF7-MESSAGE-FILTER-XSS-CVE-2025-46242",
      "plugin_slug": "cf7-message-filter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-46242",
      "affected_versions": [
        "1.6.3.9",
        "1.6.4.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 71,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46242",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CF7-SPREADSHEETS-XSS-CWE-79",
      "plugin_slug": "cf7-spreadsheets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CF7-STYLER-XSS-CVE-2025-22519",
      "plugin_slug": "cf7-styler",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22519",
      "affected_versions": [
        "1.8.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22519",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CF7-SUBMISSIONS-XSS-CVE-2025-57991",
      "plugin_slug": "cf7-submissions",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-57991",
      "affected_versions": [
        "0.27"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57991",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CHAINED-QUIZ-XSS-CVE-2025-24703",
      "plugin_slug": "chained-quiz",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24703",
      "affected_versions": [
        "1.4.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24703",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CHAMELEON-JOBS-XSS-CVE-2024-9635",
      "plugin_slug": "chameleon-jobs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-9635",
      "affected_versions": [
        "2.5.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9635",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CHANGE-WP-ADMIN-LOGIN-XSS-CWE-79",
      "plugin_slug": "change-wp-admin-login",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CHAT-ON-DESK-RCE-CWE-94",
      "plugin_slug": "chat-on-desk",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "1.0.8",
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHAT-ON-DESK-RCE-CWE-95",
      "plugin_slug": "chat-on-desk",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "1.0.8",
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHAT2-SQLI-CVE-2019-7316",
      "plugin_slug": "chat2",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2019-7316",
      "affected_versions": [
        "4.1",
        "4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-7316",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CHATBOT-CSRF-CVE-2026-40790",
      "plugin_slug": "chatbot",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-40790",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40790",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CHATBOT-SQLI-CVE-2025-8783",
      "plugin_slug": "chatbot",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-8783",
      "affected_versions": [
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHATBOT-SQLI-CVE-2025-8783",
      "plugin_slug": "chatbot",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-8783",
      "affected_versions": [
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 63,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHATBOT-SSRF-CVE-2025-8783",
      "plugin_slug": "chatbot",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-8783",
      "affected_versions": [
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 81,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHATBOT-SSRF-CVE-2025-8783",
      "plugin_slug": "chatbot",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-8783",
      "affected_versions": [
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHATBOT-XSS-CVE-2025-8783",
      "plugin_slug": "chatbot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8783",
      "affected_versions": [
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.1"
      ],
      "fixed_version": "8.5.4",
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 155,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8783",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHATBOT-XSS-CVE-2026-40790",
      "plugin_slug": "chatbot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-40790",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40790",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CHECKOUTWC-LITE-XSS-CWE-79",
      "plugin_slug": "checkoutwc-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.2.0",
        "11.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-CHEYYTEC-BUSINESS-HOURS-OPEN-NOW-XSS-CWE-79",
      "plugin_slug": "cheyytec-business-hours-open-now",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-CHEYYTEC-CONTENT-WARNING-BLUR-XSS-CWE-79",
      "plugin_slug": "cheyytec-content-warning-blur",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-CHEYYTEC-RESTAURANT-MENU-BOARD-XSS-CWE-79",
      "plugin_slug": "cheyytec-restaurant-menu-board",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-CHOYAL-SUBSCRIPTION-POPUP-SQLI-CWE-89",
      "plugin_slug": "choyal-subscription-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHOYAL-SUBSCRIPTION-POPUP-SQLI-CWE-89",
      "plugin_slug": "choyal-subscription-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CHURCH-ADMIN-XSS-CVE-2025-1457",
      "plugin_slug": "church-admin",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1457",
      "affected_versions": [
        "5.1.0",
        "5.1.1",
        "5.1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 166,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1457",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CLASSIFIED-LISTING-SSRF-CVE-2026-42660",
      "plugin_slug": "classified-listing",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-42660",
      "affected_versions": [
        "5.5.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42660",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-CLASSIFIED-LISTING-SSRF-CVE-2026-42660",
      "plugin_slug": "classified-listing",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-42660",
      "affected_versions": [
        "5.5.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42660",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CLASSIFIED-LISTING-XSS-CVE-2026-42660",
      "plugin_slug": "classified-listing",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-42660",
      "affected_versions": [
        "5.5.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42660",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CLEARFY-SSRF-CVE-2025-32544",
      "plugin_slug": "clearfy",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-32544",
      "affected_versions": [
        "2.4.2",
        "2.4.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32544",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CLEARFY-SSRF-CVE-2025-32544",
      "plugin_slug": "clearfy",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-32544",
      "affected_versions": [
        "2.4.2",
        "2.4.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32544",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CLEVER-MEGA-MENU-XSS-CWE-79",
      "plugin_slug": "clever-mega-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CLONABLE-XSS-CWE-79",
      "plugin_slug": "clonable",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.12.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CLOUD-SSO-SINGLE-SIGN-ON-XSS-CVE-2025-53567",
      "plugin_slug": "cloud-sso-single-sign-on",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53567",
      "affected_versions": [
        "1.0.21"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53567",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CLOUDSCALE-SEO-AI-OPTIMIZER-SSRF-CWE-918",
      "plugin_slug": "cloudscale-seo-ai-optimizer",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.21.365",
        "4.21.439",
        "4.21.440",
        "4.21.441"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CLOUDSCALE-SEO-AI-OPTIMIZER-SSRF-CWE-918",
      "plugin_slug": "cloudscale-seo-ai-optimizer",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.21.365",
        "4.21.439",
        "4.21.440",
        "4.21.441"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "warn",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CLOVER-ONLINE-ORDERS-SSRF-CWE-918",
      "plugin_slug": "clover-online-orders",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.6.1",
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CLOVER-ONLINE-ORDERS-SSRF-CWE-918",
      "plugin_slug": "clover-online-orders",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.6.1",
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CLP-CUSTOM-LOGIN-PAGE-XSS-CWE-79",
      "plugin_slug": "clp-custom-login-page",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CM-AD-CHANGER-XSS-CVE-2025-46246",
      "plugin_slug": "cm-ad-changer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-46246",
      "affected_versions": [
        "2.0.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46246",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CM-ANSWERS-XSS-CVE-2024-11724",
      "plugin_slug": "cm-answers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11724",
      "affected_versions": [
        "3.4.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11724",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CM-BUSINESS-DIRECTORY-XSS-CVE-2025-58001",
      "plugin_slug": "cm-business-directory",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58001",
      "affected_versions": [
        "1.5.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58001",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-CUSTOM-REPORTS-XSS-CWE-79",
      "plugin_slug": "cm-custom-reports",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-EMAIL-BLACKLIST-XSS-CVE-2024-12878",
      "plugin_slug": "cm-email-blacklist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12878",
      "affected_versions": [
        "1.6.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12878",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-FAQ-XSS-CVE-2025-28905",
      "plugin_slug": "cm-faq",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-28905",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-28905",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-FOOTNOTES-XSS-CWE-79",
      "plugin_slug": "cm-footnotes",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CM-HEADER-FOOTER-SCRIPT-LOADER-XSS-CWE-79",
      "plugin_slug": "cm-header-footer-script-loader",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-MAP-LOCATIONS-XSS-CWE-79",
      "plugin_slug": "cm-map-locations",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-ON-DEMAND-SEARCH-AND-REPLACE-XSS-CVE-2025-49891",
      "plugin_slug": "cm-on-demand-search-and-replace",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49891",
      "affected_versions": [
        "1.5.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49891",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-POP-UP-BANNERS-XSS-CVE-2025-6781",
      "plugin_slug": "cm-pop-up-banners",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-6781",
      "affected_versions": [
        "1.8.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6781",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CM-VIDEO-LESSON-MANAGER-XSS-CWE-79",
      "plugin_slug": "cm-video-lesson-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CODEBARD-HELP-DESK-XSS-CVE-2024-56218",
      "plugin_slug": "codebard-help-desk",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56218",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56218",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CODEBARD-HELP-DESK-XSS-CVE-2024-56218",
      "plugin_slug": "codebard-help-desk",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-56218",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56218",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COLETE-ONLINE-XSS-CWE-79",
      "plugin_slug": "colete-online",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.0",
        "2.2.1",
        "2.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-COLLAGE-FOR-DIVI-XSS-CWE-79",
      "plugin_slug": "collage-for-divi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-COMIC-COLLECTOR-SSRF-CWE-918",
      "plugin_slug": "comic-collector",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.7.0",
        "2.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-COMIC-COLLECTOR-SSRF-CWE-918",
      "plugin_slug": "comic-collector",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.7.0",
        "2.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-COMMENTS-CAPCHA-BOX-XSS-CVE-2025-8280",
      "plugin_slug": "comments-capcha-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8280",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8280",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COMMERCE-COINBASE-FOR-WOOCOMMERCE-XSS-CVE-2026-25035",
      "plugin_slug": "commerce-coinbase-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25035",
      "affected_versions": [
        "1.6.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COMMONS-IN-A-BOX-XSS-CWE-79",
      "plugin_slug": "commons-in-a-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.0",
        "1.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 42,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-COMMONSBOOKING-XSS-CWE-79",
      "plugin_slug": "commonsbooking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-COMMUNITY-EVENTS-SQLI-CVE-2025-12451",
      "plugin_slug": "community-events",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-12451",
      "affected_versions": [
        "1.5.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12451",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COMMUNITY-EVENTS-SQLI-CVE-2025-12451",
      "plugin_slug": "community-events",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-12451",
      "affected_versions": [
        "1.5.9"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12451",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COMMUNITY-EVENTS-XSS-CVE-2025-12451",
      "plugin_slug": "community-events",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12451",
      "affected_versions": [
        "1.5.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12451",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COMPLIANZ-GDPR-XSS-CVE-2026-42657",
      "plugin_slug": "complianz-gdpr",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-42657",
      "affected_versions": [
        "7.5.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42657",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-CONDITIONAL-MENUS-XSS-CVE-2026-32483",
      "plugin_slug": "conditional-menus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-32483",
      "affected_versions": [
        "1.2.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-32483",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONDITIONAL-QUANTITY-MANAGER-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "conditional-quantity-manager-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONNECT-DAILY-WEB-CALENDAR-XSS-CVE-2025-32520",
      "plugin_slug": "connect-daily-web-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32520",
      "affected_versions": [
        "1.5.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32520",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-7-HONEYPOT-XSS-CWE-79",
      "plugin_slug": "contact-form-7-honeypot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-DB-DIVI-XSS-CWE-79",
      "plugin_slug": "contact-form-db-divi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.3",
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-ENTRIES-XSS-CVE-2026-24380",
      "plugin_slug": "contact-form-entries",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-24380",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-24380",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-TO-EMAIL-SQLI-CVE-2025-13312",
      "plugin_slug": "contact-form-to-email",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-13312",
      "affected_versions": [
        "1.3.67"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13312",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-TO-EMAIL-SQLI-CVE-2025-13312",
      "plugin_slug": "contact-form-to-email",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-13312",
      "affected_versions": [
        "1.3.67"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13312",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORM-TO-EMAIL-XSS-CVE-2025-13312",
      "plugin_slug": "contact-form-to-email",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-13312",
      "affected_versions": [
        "1.3.67"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13312",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORMS-SQLI-CVE-2024-13372",
      "plugin_slug": "contact-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-13372",
      "affected_versions": [
        "2.2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13372",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORMS-SQLI-CVE-2025-49293",
      "plugin_slug": "contact-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-49293",
      "affected_versions": [
        "2.2.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49293",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-CONTACT-FORMS-SQLI-CVE-2024-13372",
      "plugin_slug": "contact-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-13372",
      "affected_versions": [
        "2.2.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13372",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACT-FORMS-SQLI-CVE-2025-49293",
      "plugin_slug": "contact-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-49293",
      "affected_versions": [
        "2.2.32"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49293",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-CONTACT-FORMS-XSS-CVE-2024-13372",
      "plugin_slug": "contact-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13372",
      "affected_versions": [
        "2.2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13372",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTACTIN-XSS-CWE-79",
      "plugin_slug": "contactin",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTENT-AWARE-SIDEBARS-XSS-CWE-79",
      "plugin_slug": "content-aware-sidebars",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.21.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CONTENT-EGG-XSS-CWE-79",
      "plugin_slug": "content-egg",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.3.0",
        "11.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTENT-GRID-SLIDER-XSS-CWE-79",
      "plugin_slug": "content-grid-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTENT-PROTECTOR-XSS-CVE-2026-22350",
      "plugin_slug": "content-protector",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-22350",
      "affected_versions": [
        "4.3.5",
        "4.3.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-22350",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTENT-SNIPPET-MANAGER-XSS-CVE-2025-26585",
      "plugin_slug": "content-snippet-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-26585",
      "affected_versions": [
        "1.1.9",
        "1.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26585",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTENT-TABLE-XSS-CVE-2025-58611",
      "plugin_slug": "content-table",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58611",
      "affected_versions": [
        "1.5.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58611",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTENT-VIEWS-QUERY-AND-DISPLAY-POST-PAGE-XSS-CWE-79",
      "plugin_slug": "content-views-query-and-display-post-page",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTEST-CODE-CHECKER-XSS-CVE-2025-39404",
      "plugin_slug": "contest-code-checker",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39404",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39404",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONTEST-GALLERY-SQLI-CWE-89",
      "plugin_slug": "contest-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "30.0.5",
        "30.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTEST-GALLERY-SQLI-CWE-89",
      "plugin_slug": "contest-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "30.0.5",
        "30.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 257,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONTEST-GALLERY-XSS-CWE-79",
      "plugin_slug": "contest-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "30.0.5",
        "30.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 397,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CONVERTFORCE-POPUP-BUILDER-XSS-CWE-79",
      "plugin_slug": "convertforce-popup-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0",
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CONVERTKIT-XSS-CWE-79",
      "plugin_slug": "convertkit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.4",
        "3.3.6",
        "3.3.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CORNERSTONE-XSS-CVE-2026-49780",
      "plugin_slug": "cornerstone",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-49780",
      "affected_versions": [
        "0.8.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-49780",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-COSCHOOL-SQLI-CVE-2025-47645",
      "plugin_slug": "coschool",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-47645",
      "affected_versions": [
        "1.4.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47645",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COSCHOOL-SQLI-CVE-2025-47645",
      "plugin_slug": "coschool",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-47645",
      "affected_versions": [
        "1.4.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47645",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COSCHOOL-XSS-CVE-2025-47645",
      "plugin_slug": "coschool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47645",
      "affected_versions": [
        "1.4.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 30,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47645",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-BROKEN-ACCESS-CONTROL-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-CSRF-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-KNOWN-CVE-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-472",
      "severity": "medium",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-SQLI-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-SQLI-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COST-CALCULATOR-BUILDER-XSS-CVE-2025-2010",
      "plugin_slug": "cost-calculator-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-2010",
      "affected_versions": [
        "2.0.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COUNTDOWN-BUILDER-BROKEN-ACCESS-CONTROL-CVE-2025-2933",
      "plugin_slug": "countdown-builder",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-2933",
      "affected_versions": [
        "1.1.2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2933",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COUNTDOWN-BUILDER-KNOWN-CVE-CVE-2025-2933",
      "plugin_slug": "countdown-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "low",
      "cve": "CVE-2025-2933",
      "affected_versions": [
        "1.1.2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2933",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COUNTDOWN-BUILDER-XSS-CVE-2025-2933",
      "plugin_slug": "countdown-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-2933",
      "affected_versions": [
        "1.1.2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2933",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-COURT-RESERVATION-XSS-CVE-2025-68037",
      "plugin_slug": "court-reservation",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68037",
      "affected_versions": [
        "1.11.0",
        "1.11.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 97,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68037",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-COZY-ADDONS-XSS-CWE-79",
      "plugin_slug": "cozy-addons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-COZY-ADDONS-XSS-CVE-2024-13702",
      "plugin_slug": "cozy-addons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13702",
      "affected_versions": [
        "2.2.10",
        "2.2.12",
        "2.2.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13702",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CP-CONTACT-FORM-WITH-PAYPAL-SQLI-CVE-2025-0365",
      "plugin_slug": "cp-contact-form-with-paypal",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-0365",
      "affected_versions": [
        "1.3.66"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0365",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CP-CONTACT-FORM-WITH-PAYPAL-SQLI-CVE-2025-0365",
      "plugin_slug": "cp-contact-form-with-paypal",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-0365",
      "affected_versions": [
        "1.3.66"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0365",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CP-EASY-FORM-BUILDER-SQLI-CWE-89",
      "plugin_slug": "cp-easy-form-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.2.48"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CP-EASY-FORM-BUILDER-SQLI-CWE-89",
      "plugin_slug": "cp-easy-form-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.2.48"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CP-POLLS-SQLI-CWE-89",
      "plugin_slug": "cp-polls",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.84"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CQI-REFERRER-ATTRIBUTION-XSS-CWE-79",
      "plugin_slug": "cqi-referrer-attribution",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.10.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CRITIQUE-LFI-CVE-2025-53433",
      "plugin_slug": "critique",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2025-53433",
      "affected_versions": [
        "1.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53433",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CRM-MEMBERSHIPS-XSS-CVE-2025-13542",
      "plugin_slug": "crm-memberships",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-13542",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13542",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-CROPREFINE-XSS-CVE-2025-8113",
      "plugin_slug": "croprefine",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8113",
      "affected_versions": [
        "1.2.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8113",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CRYPTO-KNOWN-CVE-CVE-2017-3204",
      "plugin_slug": "crypto",
      "vuln_class": "known-cve",
      "cwe": "CWE-310",
      "severity": "high",
      "cve": "CVE-2017-3204",
      "affected_versions": [
        "3.0.0",
        "3.0.2",
        "3.0.3",
        "3.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2017-3204",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-CS-GALLERY-SQLI-CWE-89",
      "plugin_slug": "cs-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CS-GALLERY-SQLI-CWE-89",
      "plugin_slug": "cs-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CSS-JS-MANAGER-XSS-CWE-79",
      "plugin_slug": "css-js-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.49.73"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-CTC-LITE-XSS-CWE-79",
      "plugin_slug": "ctc-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CURRENCY-SWITCHER-XSS-CVE-2025-1561",
      "plugin_slug": "currency-switcher",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1561",
      "affected_versions": [
        "1.3.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1561",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CURRENCY-SWITCHER-FOR-WOOCOMMERCE-KNOWN-CVE-CVE-2025-30888",
      "plugin_slug": "currency-switcher-for-woocommerce",
      "vuln_class": "known-cve",
      "cwe": "CWE-755",
      "severity": "medium",
      "cve": "CVE-2025-30888",
      "affected_versions": [
        "0.0.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30888",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CUSTOM-PAGE-MENUS-XSS-CWE-79",
      "plugin_slug": "custom-page-menus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-CUSTOM-REGISTRATION-FORM-BUILDER-WITH-SUBMISSION-MANAGER-XSS-CWE-79",
      "plugin_slug": "custom-registration-form-builder-with-submission-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.0.9.4",
        "6.0.9.5",
        "6.0.9.6",
        "6.0.9.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 69,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-CUSTOMCOMMENT-XSS-CVE-2025-49047",
      "plugin_slug": "customcomment",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49047",
      "affected_versions": [
        "2.1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49047",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-CUSTOMIZER-LOGIN-PAGE-XSS-CVE-2025-11835",
      "plugin_slug": "customizer-login-page",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11835",
      "affected_versions": [
        "2.1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11835",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DAAZSYNC-XSS-CWE-79",
      "plugin_slug": "daazsync",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-DARKPILOT-XSS-CWE-79",
      "plugin_slug": "darkpilot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-DASHBOARD-FEEDS-DASHBOARD-WIDGET-XSS-CWE-79",
      "plugin_slug": "dashboard-feeds-dashboard-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DASHBOARDPLUS-XSS-CWE-79",
      "plugin_slug": "dashboardplus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DATABASE-TO-EXCEL-SQLI-CVE-2025-58818",
      "plugin_slug": "database-to-excel",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-58818",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DATABASE-TO-EXCEL-SQLI-CVE-2025-58818",
      "plugin_slug": "database-to-excel",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-58818",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DATABASE-TO-EXCEL-XSS-CVE-2025-58818",
      "plugin_slug": "database-to-excel",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58818",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DATAFEEDR-COMPARISON-SETS-XSS-CWE-79",
      "plugin_slug": "datafeedr-comparison-sets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.9.81"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 81,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DEBOUNCE-IO-EMAIL-VALIDATOR-SSRF-CWE-918",
      "plugin_slug": "debounce-io-email-validator",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "5.8.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DEBOUNCE-IO-EMAIL-VALIDATOR-SSRF-CWE-918",
      "plugin_slug": "debounce-io-email-validator",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "5.8.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DEBUG-LOG-VIEWER-XSS-CVE-2025-8383",
      "plugin_slug": "debug-log-viewer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8383",
      "affected_versions": [
        "2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8383",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DELETE-ALL-COMMENTS-OF-WEBSITE-XSS-CWE-79",
      "plugin_slug": "delete-all-comments-of-website",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-DELETE-OLD-POSTS-PROGRAMMATICALLY-XSS-CWE-79",
      "plugin_slug": "delete-old-posts-programmatically",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.13.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DELICIOUS-RECIPES-XSS-CVE-2026-27388",
      "plugin_slug": "delicious-recipes",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-27388",
      "affected_versions": [
        "1.10.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27388",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DEMO-IMPORTER-PLUS-XSS-CVE-2025-68897",
      "plugin_slug": "demo-importer-plus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-68897",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68897",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-DEMOCRACY-POLL-SQLI-CWE-89",
      "plugin_slug": "democracy-poll",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "6.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-DEMOCRACY-POLL-SQLI-CWE-89",
      "plugin_slug": "democracy-poll",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "6.4.0",
        "6.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DEPLOYER-FOR-GIT-XSS-CWE-79",
      "plugin_slug": "deployer-for-git",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-26"
    },
    {
      "id": "CLR-WP-DEVDIGGERS-WALLET-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "devdiggers-wallet-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-DEVDOME-SAFE-MEDIA-CLEANER-SSRF-CWE-918",
      "plugin_slug": "devdome-safe-media-cleaner",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-DEVDOME-SAFE-MEDIA-CLEANER-SSRF-CWE-918",
      "plugin_slug": "devdome-safe-media-cleaner",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-DEVELOPER-TOOL-XSS-CWE-79",
      "plugin_slug": "developer-tool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DIGITIMBER-CPANEL-INTEGRATION-XSS-CVE-2025-22705",
      "plugin_slug": "digitimber-cpanel-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22705",
      "affected_versions": [
        "1.4.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22705",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DINATUR-XSS-CWE-79",
      "plugin_slug": "dinatur",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DIRECT-PAYMENTS-WP-SSRF-CVE-2026-27387",
      "plugin_slug": "direct-payments-wp",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-27387",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27387",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DIRECT-PAYMENTS-WP-SSRF-CVE-2026-27387",
      "plugin_slug": "direct-payments-wp",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-27387",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27387",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DIRECTIQ-WP-SQLI-CWE-89",
      "plugin_slug": "directiq-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DIRECTIQ-WP-SQLI-CWE-89",
      "plugin_slug": "directiq-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DISABLE-RIGHT-CLICK-FOR-WP-CSRF-CVE-2022-29427",
      "plugin_slug": "disable-right-click-for-wp",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2022-29427",
      "affected_versions": [
        "1.1.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-29427",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-DISTANCE-BASED-SHIPPING-CALCULATOR-XSS-CVE-2025-1402",
      "plugin_slug": "distance-based-shipping-calculator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1402",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1402",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DOKAN-KITS-XSS-CWE-79",
      "plugin_slug": "dokan-kits",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.6",
        "3.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-DOLICONNECT-XSS-CWE-79",
      "plugin_slug": "doliconnect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "10.2.0",
        "10.3.1",
        "10.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DONEREN-MET-MOLLIE-XSS-CWE-79",
      "plugin_slug": "doneren-met-mollie",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.10.11",
        "2.11.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DOT-HTMLPHPXML-ETC-PAGES-XSS-CVE-2025-31055",
      "plugin_slug": "dot-htmlphpxml-etc-pages",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31055",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31055",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DOUBLEDOME-RESOURCE-LINK-LIBRARY-SQLI-CVE-2025-64244",
      "plugin_slug": "doubledome-resource-link-library",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-64244",
      "affected_versions": [
        "1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-64244",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DOUBLEDOME-RESOURCE-LINK-LIBRARY-SQLI-CVE-2025-64244",
      "plugin_slug": "doubledome-resource-link-library",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-64244",
      "affected_versions": [
        "1.6"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-64244",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-DOUBLESCALE-XSS-CWE-79",
      "plugin_slug": "doublescale",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.14",
        "1.2.15",
        "1.2.16",
        "1.2.17"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-BROKEN-ACCESS-CONTROL-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-BROKEN-ACCESS-CONTROL-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-FILE-UPLOAD-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-KNOWN-CVE-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-KNOWN-CVE-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "known-cve",
      "cwe": "CWE-552",
      "severity": "medium",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-SQLI-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-SSRF-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-XSS-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "low",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DOWNLOAD-MONITOR-XSS-CVE-2025-15441",
      "plugin_slug": "download-monitor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-15441",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15441",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DRAG-AND-DROP-MULTIPLE-FILE-UPLOAD-FOR-WOOCOMMERCE-FILE-UPLOAD-CVE-2025-30582",
      "plugin_slug": "drag-and-drop-multiple-file-upload-for-woocommerce",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "medium",
      "cve": "CVE-2025-30582",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30582",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-DROP-SHADOW-BOXES-XSS-CWE-79",
      "plugin_slug": "drop-shadow-boxes",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-DROPSHIPPING-XOX-XSS-CWE-79",
      "plugin_slug": "dropshipping-xox",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-E-BOEKHOUDENNL-CONNECTOR-XSS-CWE-79",
      "plugin_slug": "e-boekhoudennl-connector",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-E-TRANSACTIONS-WC-XSS-CWE-79",
      "plugin_slug": "e-transactions-wc",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-E2PDF-BROKEN-ACCESS-CONTROL-CVE-2026-54805",
      "plugin_slug": "e2pdf",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2026-54805",
      "affected_versions": [
        "1.03.07"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-E2PDF-CSRF-CVE-2026-54805",
      "plugin_slug": "e2pdf",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-54805",
      "affected_versions": [
        "1.03.07"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-E2PDF-DESERIALIZATION-CVE-2026-54805",
      "plugin_slug": "e2pdf",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "medium",
      "cve": "CVE-2026-54805",
      "affected_versions": [
        "1.03.07"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-E2PDF-FILE-UPLOAD-CVE-2026-54805",
      "plugin_slug": "e2pdf",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2026-54805",
      "affected_versions": [
        "1.03.07"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-E2PDF-XSS-CVE-2026-54805",
      "plugin_slug": "e2pdf",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-54805",
      "affected_versions": [
        "1.03.07"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EAFATURA-E-ARSIV-ENTEGRASYON-XSS-CWE-79",
      "plugin_slug": "eafatura-e-arsiv-entegrasyon",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.7.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-EASY-APPOINTMENTS-SQLI-CWE-89",
      "plugin_slug": "easy-appointments",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.12.28"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EASY-APPOINTMENTS-SQLI-CWE-89",
      "plugin_slug": "easy-appointments",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.12.28"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EASY-DIGITAL-DOWNLOADS-XSS-CVE-2026-25440",
      "plugin_slug": "easy-digital-downloads",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25440",
      "affected_versions": [
        "3.6.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25440",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-EASY-FATTURA-ELETTRONICA-FREE-SQLI-CWE-89",
      "plugin_slug": "easy-fattura-elettronica-free",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.6.26",
        "1.6.27"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-EASY-FATTURA-ELETTRONICA-FREE-SQLI-CWE-89",
      "plugin_slug": "easy-fattura-elettronica-free",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.6.26",
        "1.6.27"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-EASY-IMAGE-FILTERS-XSS-CWE-79",
      "plugin_slug": "easy-image-filters",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EASY-POPUPS-XSS-CWE-79",
      "plugin_slug": "easy-popups",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EASY-UPLOAD-FILES-DURING-CHECKOUT-XSS-CVE-2026-57705",
      "plugin_slug": "easy-upload-files-during-checkout",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-57705",
      "affected_versions": [
        "3.0.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57705",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EASY-ZILLOW-REVIEWS-XSS-CWE-79",
      "plugin_slug": "easy-zillow-reviews",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EASYCOMMERCE-SSRF-CVE-2025-12813",
      "plugin_slug": "easycommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-12813",
      "affected_versions": [
        "1.44",
        "1.45",
        "1.46"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12813",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-EASYCOMMERCE-SSRF-CVE-2025-12813",
      "plugin_slug": "easycommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-12813",
      "affected_versions": [
        "1.44",
        "1.45",
        "1.46"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12813",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-EASYJOBS-XSS-CWE-79",
      "plugin_slug": "easyjobs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 88,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-EASYNC-BOOKING-XSS-CVE-2025-31406",
      "plugin_slug": "easync-booking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31406",
      "affected_versions": [
        "1.3.29"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31406",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EASYPARCEL-SHIPPING-XSS-CWE-79",
      "plugin_slug": "easyparcel-shipping",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.61",
        "1.0.62",
        "1.0.63",
        "1.0.64"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-EBENE-EQUIPMENT-RENTAL-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "ebene-equipment-rental-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ECOMMERCE-PRODUCT-CATALOG-XSS-CVE-2024-56213",
      "plugin_slug": "ecommerce-product-catalog",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56213",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56213",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ECPAY-ECOMMERCE-FOR-WOOCOMMERCE-XSS-CVE-2024-8494",
      "plugin_slug": "ecpay-ecommerce-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-8494",
      "affected_versions": [
        "1.1.2606090"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8494",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EDENPERSONA-CONNECTOR-ANALYTICS-XSS-CWE-79",
      "plugin_slug": "edenpersona-connector-analytics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-EDITORIAL-CALENDAR-XSS-CVE-2026-32352",
      "plugin_slug": "editorial-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-32352",
      "affected_versions": [
        "3.9.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-32352",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EDUADMIN-BOOKING-XSS-CWE-79",
      "plugin_slug": "eduadmin-booking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EDUCARE-SQLI-CWE-89",
      "plugin_slug": "educare",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EDUCARE-SQLI-CWE-89",
      "plugin_slug": "educare",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EDUCARE-XSS-CWE-79",
      "plugin_slug": "educare",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 31,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EFFECT-MAKER-SQLI-CVE-2025-11220",
      "plugin_slug": "effect-maker",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-11220",
      "affected_versions": [
        "1.2.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11220",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EFFECT-MAKER-SQLI-CVE-2025-11220",
      "plugin_slug": "effect-maker",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-11220",
      "affected_versions": [
        "1.2.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11220",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ELEARNING-MEMBERSHIPS-XSS-CWE-79",
      "plugin_slug": "elearning-memberships",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ELEGANT-CALENDAR-LITE-XSS-CWE-79",
      "plugin_slug": "elegant-calendar-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.17"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ELEMENTINVADER-XSS-CVE-2025-31413",
      "plugin_slug": "elementinvader",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31413",
      "affected_versions": [
        "1.2.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31413",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ELEMENTSKIT-LITE-XSS-CVE-2024-13520",
      "plugin_slug": "elementskit-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13520",
      "affected_versions": [
        "3.10.01"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13520",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ELFSIGHT-TESTIMONIALS-SLIDER-XSS-CVE-2025-0671",
      "plugin_slug": "elfsight-testimonials-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-0671",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0671",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ELISQLREPORTS-XSS-CWE-79",
      "plugin_slug": "elisqlreports",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.25.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMAIL-SHORTCODE-SQLI-CVE-2025-39597",
      "plugin_slug": "email-shortcode",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-39597",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39597",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMAIL-SHORTCODE-SQLI-CVE-2025-39597",
      "plugin_slug": "email-shortcode",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-39597",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39597",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMAIL-SHORTCODE-XSS-CVE-2025-39597",
      "plugin_slug": "email-shortcode",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39597",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39597",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMAIL-SUBSCRIBERS-XSS-CVE-2026-2899",
      "plugin_slug": "email-subscribers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-2899",
      "affected_versions": [
        "5.9.31",
        "5.9.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-2899",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-EMAIL-TRACKER-SQLI-CWE-89",
      "plugin_slug": "email-tracker",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.3.16"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMAIL-TRACKER-SQLI-CWE-89",
      "plugin_slug": "email-tracker",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.3.16"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMARKSHEET-SQLI-CWE-89",
      "plugin_slug": "emarksheet",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMARKSHEET-SQLI-CWE-89",
      "plugin_slug": "emarksheet",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EMBEDDER-FOR-GOOGLE-REVIEWS-XSS-CVE-2025-54692",
      "plugin_slug": "embedder-for-google-reviews",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-54692",
      "affected_versions": [
        "2.1",
        "2.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54692",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-EMBEDPRESS-SSRF-CWE-918",
      "plugin_slug": "embedpress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.6.0",
        "4.6.1",
        "4.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EMBEDPRESS-SSRF-CWE-918",
      "plugin_slug": "embedpress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.6.0",
        "4.6.1",
        "4.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ENABLE-LATEX-XSS-CVE-2025-58806",
      "plugin_slug": "enable-latex",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58806",
      "affected_versions": [
        "1.2.16"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 35,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58806",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ENHANCED-TOOLTIPGLOSSARY-XSS-CWE-79",
      "plugin_slug": "enhanced-tooltipglossary",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ENTERADDONS-SSRF-CWE-918",
      "plugin_slug": "enteraddons",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ENTERADDONS-SSRF-CWE-918",
      "plugin_slug": "enteraddons",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ENTRIES-MANAGER-XSS-CWE-79",
      "plugin_slug": "entries-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-ENTRYWIZARD-XSS-CWE-79",
      "plugin_slug": "entrywizard",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.33",
        "1.3.34"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-ENVO-ELEMENTOR-FOR-WOOCOMMERCE-SSRF-CVE-2026-57730",
      "plugin_slug": "envo-elementor-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-57730",
      "affected_versions": [
        "1.4.27"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57730",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ENVO-ELEMENTOR-FOR-WOOCOMMERCE-SSRF-CVE-2026-57730",
      "plugin_slug": "envo-elementor-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-57730",
      "affected_versions": [
        "1.4.27"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57730",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EPEKEN-ALL-KURIR-SSRF-CVE-2025-3421",
      "plugin_slug": "epeken-all-kurir",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-3421",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-3421",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EPEKEN-ALL-KURIR-SSRF-CVE-2025-3421",
      "plugin_slug": "epeken-all-kurir",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-3421",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-3421",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EPEKEN-ALL-KURIR-XSS-CVE-2025-3421",
      "plugin_slug": "epeken-all-kurir",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-3421",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-3421",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EPICWIN-SUBSCRIBERS-XSS-CVE-2025-49238",
      "plugin_slug": "epicwin-subscribers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49238",
      "affected_versions": [
        "1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49238",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ERP-FILE-UPLOAD-CVE-2025-10304",
      "plugin_slug": "erp",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2025-10304",
      "affected_versions": [
        "1.17.6",
        "1.17.7"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10304",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ERP-SQLI-CVE-2025-10304",
      "plugin_slug": "erp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-10304",
      "affected_versions": [
        "1.17.6",
        "1.17.7"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10304",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ERROR-LOG-MONITOR-XSS-CWE-79",
      "plugin_slug": "error-log-monitor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ESSELINKNU-SETTINGS-SQLI-CWE-89",
      "plugin_slug": "esselinknu-settings",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ESSELINKNU-SETTINGS-SQLI-CWE-89",
      "plugin_slug": "esselinknu-settings",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ESSELINKNU-SETTINGS-XSS-CWE-79",
      "plugin_slug": "esselinknu-settings",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.7",
        "4.8",
        "4.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 74,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-CSRF-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-FILE-UPLOAD-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-KNOWN-CVE-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-KNOWN-CVE-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-KNOWN-CVE-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-LFI-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-SSRF-CVE-2025-12407",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-12407",
      "affected_versions": [
        "5.3.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12407",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-SSRF-CVE-2025-12407",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-12407",
      "affected_versions": [
        "5.3.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12407",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-XSS-CVE-2025-12407",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12407",
      "affected_versions": [
        "5.3.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12407",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ESSENTIAL-REAL-ESTATE-XSS-CVE-2025-62870",
      "plugin_slug": "essential-real-estate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-62870",
      "affected_versions": [
        "1.2.7",
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62870",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESTATIK-BROKEN-ACCESS-CONTROL-CVE-2025-26907",
      "plugin_slug": "estatik",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-26907",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESTATIK-DESERIALIZATION-CVE-2025-26907",
      "plugin_slug": "estatik",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "critical",
      "cve": "CVE-2025-26907",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESTATIK-FILE-UPLOAD-CVE-2025-26907",
      "plugin_slug": "estatik",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2025-26907",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESTATIK-FILE-UPLOAD-CVE-2025-26907",
      "plugin_slug": "estatik",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "medium",
      "cve": "CVE-2025-26907",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-ESTATIK-XSS-CVE-2025-62042",
      "plugin_slug": "estatik",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62042",
      "affected_versions": [
        "4.3.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62042",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ESTATIK-XSS-CVE-2025-26907",
      "plugin_slug": "estatik",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-26907",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EUCOOKIELAW-XSS-CVE-2025-47625",
      "plugin_slug": "eucookielaw",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47625",
      "affected_versions": [
        "2.7.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47625",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EUPAGO-GATEWAY-FOR-WOOCOMMERCE-XSS-CVE-2025-12408",
      "plugin_slug": "eupago-gateway-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12408",
      "affected_versions": [
        "4.7.2",
        "4.7.3",
        "4.7.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 56,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12408",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EVENT-XSS-CVE-2024-35711",
      "plugin_slug": "event",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-35711",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-35711",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-EVENT-TICKETS-XSS-CWE-79",
      "plugin_slug": "event-tickets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.29.0",
        "5.29.0.1",
        "5.29.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTPRIME-EVENT-CALENDAR-MANAGEMENT-XSS-CVE-2024-56233",
      "plugin_slug": "eventprime-event-calendar-management",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56233",
      "affected_versions": [
        "4.3.4.3",
        "4.3.4.4",
        "4.3.4.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56233",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-ADDON-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "events-addon-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-MADE-EASY-SSRF-CWE-918",
      "plugin_slug": "events-made-easy",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.1.4",
        "3.1.5",
        "3.1.7",
        "3.1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-MADE-EASY-SSRF-CWE-918",
      "plugin_slug": "events-made-easy",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.1.4",
        "3.1.5",
        "3.1.7",
        "3.1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-MADE-EASY-XSS-CWE-79",
      "plugin_slug": "events-made-easy",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.4",
        "3.1.5",
        "3.1.7",
        "3.1.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 235,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-MAKER-XSS-CWE-79",
      "plugin_slug": "events-maker",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVENTS-MANAGER-XSS-CWE-79",
      "plugin_slug": "events-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.4.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVEREST-BACKUP-XSS-CVE-2025-11166",
      "plugin_slug": "everest-backup",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11166",
      "affected_versions": [
        "2.3.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11166",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-BROKEN-ACCESS-CONTROL-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-DESERIALIZATION-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "critical",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-FILE-UPLOAD-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-KNOWN-CVE-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "known-cve",
      "cwe": "CWE-36",
      "severity": "high",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-RCE-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-SQLI-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-SSRF-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-XSS-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "low",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EVEREST-FORMS-XSS-CVE-2026-39446",
      "plugin_slug": "everest-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-39446",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39446",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-EWZ-RATING-XSS-CWE-79",
      "plugin_slug": "ewz-rating",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.43"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-EXCLUSIVE-BLOCKS-XSS-CWE-79",
      "plugin_slug": "exclusive-blocks",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXHIBIT-TO-WP-GALLERY-SQLI-CVE-2024-11457",
      "plugin_slug": "exhibit-to-wp-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-11457",
      "affected_versions": [
        "0.002"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11457",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXHIBIT-TO-WP-GALLERY-SQLI-CVE-2024-11457",
      "plugin_slug": "exhibit-to-wp-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-11457",
      "affected_versions": [
        "0.002"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11457",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXHIBIT-TO-WP-GALLERY-XSS-CVE-2024-11457",
      "plugin_slug": "exhibit-to-wp-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11457",
      "affected_versions": [
        "0.002"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11457",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXPERTFILE-EXPERT-CONTENT-TEMPLATES-XSS-CWE-79",
      "plugin_slug": "expertfile-expert-content-templates",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.51"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-EXPLARA-EVENTS-SQLI-CVE-2024-52471",
      "plugin_slug": "explara-events",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-52471",
      "affected_versions": [
        "0.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-52471",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXPLARA-EVENTS-SQLI-CVE-2024-52471",
      "plugin_slug": "explara-events",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-52471",
      "affected_versions": [
        "0.1.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-52471",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXPLARA-EVENTS-XSS-CVE-2024-52471",
      "plugin_slug": "explara-events",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-52471",
      "affected_versions": [
        "0.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-52471",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-EXPORT-CUSTOMERS-DATA-XSS-CWE-79",
      "plugin_slug": "export-customers-data",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-F12-PROFILER-SSRF-CWE-918",
      "plugin_slug": "f12-profiler",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-F12-PROFILER-SSRF-CWE-918",
      "plugin_slug": "f12-profiler",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-F4-TREE-XSS-CVE-2024-13221",
      "plugin_slug": "f4-tree",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13221",
      "affected_versions": [
        "2.0.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13221",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FACEBOOK-AUTO-PUBLISH-XSS-CWE-79",
      "plugin_slug": "facebook-auto-publish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FACTURA-ELECTRONICA-CR-SQLI-CWE-89",
      "plugin_slug": "factura-electronica-cr",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-FACTURA-ELECTRONICA-CR-SQLI-CWE-89",
      "plugin_slug": "factura-electronica-cr",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-FACTURA-ELECTRONICA-CR-XSS-CWE-79",
      "plugin_slug": "factura-electronica-cr",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-FALANG-XSS-CVE-2026-54196",
      "plugin_slug": "falang",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-54196",
      "affected_versions": [
        "1.4.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54196",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FAST-INDEX-XSS-CWE-79",
      "plugin_slug": "fast-index",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FB-REVIEWS-WIDGET-XSS-CWE-79",
      "plugin_slug": "fb-reviews-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FEATURED-GALLERIES-XSS-CWE-79",
      "plugin_slug": "featured-galleries",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FEATURED-IMAGE-PRO-XSS-CWE-79",
      "plugin_slug": "featured-image-pro",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FEATURED-IMAGES-FOR-RSS-FEEDS-XSS-CWE-79",
      "plugin_slug": "featured-images-for-rss-feeds",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FEATURED-POST-XSS-CWE-79",
      "plugin_slug": "featured-post",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FEED-THEM-SOCIAL-XSS-CWE-79",
      "plugin_slug": "feed-them-social",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 33,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-CSRF-CVE-2024-1538",
      "plugin_slug": "file-manager",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2024-1538",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-1538",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-CSRF-CVE-2024-8507",
      "plugin_slug": "file-manager",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2024-8507",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8507",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-FILE-UPLOAD-CVE-2024-8746",
      "plugin_slug": "file-manager",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2024-8746",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8746",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-FILE-UPLOAD-CVE-2024-8918",
      "plugin_slug": "file-manager",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2024-8918",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8918",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-KNOWN-CVE-CVE-2024-0761",
      "plugin_slug": "file-manager",
      "vuln_class": "known-cve",
      "cwe": "CWE-330",
      "severity": "high",
      "cve": "CVE-2024-0761",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-0761",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-KNOWN-CVE-CVE-2024-2654",
      "plugin_slug": "file-manager",
      "vuln_class": "known-cve",
      "cwe": "CWE-35",
      "severity": "medium",
      "cve": "CVE-2024-2654",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-2654",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-LFI-CVE-2023-6825",
      "plugin_slug": "file-manager",
      "vuln_class": "lfi",
      "cwe": "CWE-23",
      "severity": "critical",
      "cve": "CVE-2023-6825",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-6825",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-RCE-CVE-2023-6846",
      "plugin_slug": "file-manager",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "high",
      "cve": "CVE-2023-6846",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-6846",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILE-MANAGER-XSS-CVE-2021-24177",
      "plugin_slug": "file-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24177",
      "affected_versions": [
        "6.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24177",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FILEVUE-XSS-CWE-79",
      "plugin_slug": "filevue",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.0",
        "2.6.1",
        "2.7.0",
        "2.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 65,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-FILR-PROTECTION-XSS-CWE-79",
      "plugin_slug": "filr-protection",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-FILR-PROTECTION-XSS-CVE-2025-58206",
      "plugin_slug": "filr-protection",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58206",
      "affected_versions": [
        "1.2.14"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58206",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FINAL-TILES-GRID-GALLERY-LITE-XSS-CWE-79",
      "plugin_slug": "final-tiles-grid-gallery-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.6.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FINALE-WOOCOMMERCE-SALES-COUNTDOWN-TIMER-DISCOUNT-XSS-CWE-79",
      "plugin_slug": "finale-woocommerce-sales-countdown-timer-discount",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.20.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FIRST-PARTY-ANALYTICS-XSS-CWE-79",
      "plugin_slug": "first-party-analytics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.62",
        "1.2.63"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FLEET-BROKEN-ACCESS-CONTROL-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-BROKEN-ACCESS-CONTROL-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-BROKEN-ACCESS-CONTROL-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-BROKEN-ACCESS-CONTROL-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-DOS-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "dos",
      "cwe": "CWE-400",
      "severity": "low",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-20",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-201",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-290",
      "severity": "critical",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-290",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-290",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-295",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-330",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-347",
      "severity": "critical",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-488",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-613",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-703",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-KNOWN-CVE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "known-cve",
      "cwe": "CWE-770",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-RCE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "rce",
      "cwe": "CWE-78",
      "severity": "critical",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-RCE-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "rce",
      "cwe": "CWE-78",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-SQLI-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEET-XSS-CVE-2025-12018",
      "plugin_slug": "fleet",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-12018",
      "affected_versions": [
        "2.6.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEX-TOP-BAR-XSS-CWE-79",
      "plugin_slug": "flex-top-bar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FLEXIBLE-COUPONS-XSS-CWE-79",
      "plugin_slug": "flexible-coupons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.14.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEXIBLE-FRONTEND-LOGIN-XSS-CWE-79",
      "plugin_slug": "flexible-frontend-login",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FLEXIBLE-INVOICES-XSS-CVE-2025-60172",
      "plugin_slug": "flexible-invoices",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-60172",
      "affected_versions": [
        "6.2.21"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60172",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLEXIBLE-SHIPPING-XSS-CWE-79",
      "plugin_slug": "flexible-shipping",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.10.0",
        "6.9.0",
        "6.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 52,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-FLEXOSLIDER-XSS-CWE-79",
      "plugin_slug": "flexoslider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0004"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 43,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FLIPA-PDF-FLIPBOOK-XSS-CWE-79",
      "plugin_slug": "flipa-pdf-flipbook",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.13.1",
        "0.13.3",
        "0.13.4",
        "0.14.0",
        "0.14.1",
        "0.15.1",
        "0.16.0",
        "0.16.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 106,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FLUENT-SECURITY-XSS-CVE-2025-68528",
      "plugin_slug": "fluent-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68528",
      "affected_versions": [
        "2.1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68528",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FOLDERS-CSRF-CVE-2025-13382",
      "plugin_slug": "folders",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-13382",
      "affected_versions": [
        "3.1.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13382",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FOLDERS-CSRF-CVE-2025-13382",
      "plugin_slug": "folders",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-13382",
      "affected_versions": [
        "3.1.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13382",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FOLDERS-KNOWN-CVE-CVE-2025-13382",
      "plugin_slug": "folders",
      "vuln_class": "known-cve",
      "cwe": "CWE-532",
      "severity": "medium",
      "cve": "CVE-2025-13382",
      "affected_versions": [
        "3.1.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13382",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FOLIOPRESS-WYSIWYG-XSS-CVE-2025-32659",
      "plugin_slug": "foliopress-wysiwyg",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32659",
      "affected_versions": [
        "2.6.19"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32659",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FOOBAR-NOTIFICATIONS-LITE-XSS-CWE-79",
      "plugin_slug": "foobar-notifications-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FOOBOX-IMAGE-LIGHTBOX-XSS-CVE-2025-31735",
      "plugin_slug": "foobox-image-lightbox",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31735",
      "affected_versions": [
        "2.7.43",
        "2.8.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31735",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FOOD-STORE-XSS-CWE-79",
      "plugin_slug": "food-store",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FOOGALLERY-XSS-CVE-2026-39630",
      "plugin_slug": "foogallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39630",
      "affected_versions": [
        "3.1.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39630",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FOOSALES-XSS-CWE-79",
      "plugin_slug": "foosales",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.41.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FORM-GENERATOR-POWERED-BY-JOTFORM-XSS-CWE-79",
      "plugin_slug": "form-generator-powered-by-jotform",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.52"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORMALITY-XSS-CVE-2025-7340",
      "plugin_slug": "formality",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-7340",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-7340",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-FORMESIGN-XSS-CWE-79",
      "plugin_slug": "formesign",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FORMINATOR-RCE-CVE-2025-39524",
      "plugin_slug": "forminator",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2025-39524",
      "affected_versions": [
        "1.55.1",
        "1.56.0",
        "1.56.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39524",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORMINATOR-RCE-CVE-2025-39524",
      "plugin_slug": "forminator",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "cve": "CVE-2025-39524",
      "affected_versions": [
        "1.55.1",
        "1.56.0",
        "1.56.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39524",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-FORMINATOR-XSS-CVE-2025-39524",
      "plugin_slug": "forminator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39524",
      "affected_versions": [
        "1.55.1",
        "1.56.0",
        "1.56.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 47,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39524",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORMS-BY-MADE-IT-XSS-CVE-2025-54677",
      "plugin_slug": "forms-by-made-it",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-54677",
      "affected_versions": [
        "3.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 40,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54677",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORUM-SERVER-SQLI-CVE-2025-53256",
      "plugin_slug": "forum-server",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-53256",
      "affected_versions": [
        "1.8.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 44,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53256",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORUM-SERVER-SQLI-CVE-2025-53256",
      "plugin_slug": "forum-server",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-53256",
      "affected_versions": [
        "1.8.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 38,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53256",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FORUM-SERVER-XSS-CVE-2025-53256",
      "plugin_slug": "forum-server",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53256",
      "affected_versions": [
        "1.8.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53256",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FOXTOOL-XSS-CWE-79",
      "plugin_slug": "foxtool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FOXYSHOP-SSRF-CWE-918",
      "plugin_slug": "foxyshop",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.9.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FOXYSHOP-SSRF-CWE-918",
      "plugin_slug": "foxyshop",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.9.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FRONTEND-DASHBOARD-RCE-CVE-2025-39386",
      "plugin_slug": "frontend-dashboard",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "high",
      "cve": "CVE-2025-39386",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39386",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-FRONTEND-RESET-PASSWORD-XSS-CWE-79",
      "plugin_slug": "frontend-reset-password",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FRUMBIK-AFFILIATE-HUB-XSS-CWE-79",
      "plugin_slug": "frumbik-affiliate-hub",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.3",
        "2.3.1",
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 69,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-FUERTE-WP-XSS-CWE-79",
      "plugin_slug": "fuerte-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.10.0",
        "1.11.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-FULL-PICTURE-ANALYTICS-COOKIE-NOTICE-XSS-CWE-79",
      "plugin_slug": "full-picture-analytics-cookie-notice",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "10.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FULL-WIDTH-RESPONSIVE-SLIDER-WP-SQLI-CWE-89",
      "plugin_slug": "full-width-responsive-slider-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FULL-WIDTH-RESPONSIVE-SLIDER-WP-SQLI-CWE-89",
      "plugin_slug": "full-width-responsive-slider-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FUNDPRESS-XSS-CVE-2026-42655",
      "plugin_slug": "fundpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-42655",
      "affected_versions": [
        "2.0.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42655",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FUSEDESK-XSS-CWE-79",
      "plugin_slug": "fusedesk",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2009-1244",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2009-1244",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1244",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2009-1805",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2009-1805",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-1805",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2012-1666",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2012-1666",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2012-1666",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2009-3282",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "cwe": "CWE-189",
      "severity": "medium",
      "cve": "CVE-2009-3282",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-3282",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2009-3281",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "medium",
      "cve": "CVE-2009-3281",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-3281",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-KNOWN-CVE-CVE-2009-0177",
      "plugin_slug": "fusion",
      "vuln_class": "known-cve",
      "cwe": "CWE-399",
      "severity": "medium",
      "cve": "CVE-2009-0177",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2009-0177",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUSION-XSS-CWE-79",
      "plugin_slug": "fusion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-FUSION-XSS-CVE-2012-2083",
      "plugin_slug": "fusion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2012-2083",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2012-2083",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-FUTURIO-EXTRA-XSS-CVE-2024-10178",
      "plugin_slug": "futurio-extra",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-10178",
      "affected_versions": [
        "2.0.23",
        "2.0.24"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10178",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GA-FOR-WP-XSS-CVE-2025-13812",
      "plugin_slug": "ga-for-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-13812",
      "affected_versions": [
        "2.10.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13812",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GALLERY-IMAGES-APE-XSS-CVE-2025-24608",
      "plugin_slug": "gallery-images-ape",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24608",
      "affected_versions": [
        "2.2.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24608",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GALLERY-IMAGES-APE-XSS-CVE-2025-24608",
      "plugin_slug": "gallery-images-ape",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-24608",
      "affected_versions": [
        "2.2.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24608",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GAMIPRESS-XSS-CWE-79",
      "plugin_slug": "gamipress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.9.5",
        "7.9.6",
        "7.9.7",
        "7.9.8",
        "7.9.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 68,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GARSEN-ACCESSIBILITY-GUARD-XSS-CWE-79",
      "plugin_slug": "garsen-accessibility-guard",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GATELAND-XSS-CWE-79",
      "plugin_slug": "gateland",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-GB-GALLERY-SLIDESHOW-XSS-CVE-2025-22263",
      "plugin_slug": "gb-gallery-slideshow",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22263",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22263",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GD-MAIL-QUEUE-XSS-CWE-79",
      "plugin_slug": "gd-mail-queue",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GD-RATING-SYSTEM-XSS-CVE-2026-14029",
      "plugin_slug": "gd-rating-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-14029",
      "affected_versions": [
        "3.7",
        "3.7.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-14029",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GDPR-XSS-CWE-79",
      "plugin_slug": "gdpr",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GDY-MODULAR-CONTENT-SQLI-CVE-2024-13220",
      "plugin_slug": "gdy-modular-content",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-13220",
      "affected_versions": [
        "0.11.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13220",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GDY-MODULAR-CONTENT-SQLI-CVE-2024-13220",
      "plugin_slug": "gdy-modular-content",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-13220",
      "affected_versions": [
        "0.11.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13220",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GDY-MODULAR-CONTENT-XSS-CVE-2024-13220",
      "plugin_slug": "gdy-modular-content",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13220",
      "affected_versions": [
        "0.11.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13220",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GEIDEA-ONLINE-PAYMENTS-XSS-CWE-79",
      "plugin_slug": "geidea-online-payments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GENE-SECTION-BUILDER-XSS-CWE-79",
      "plugin_slug": "gene-section-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.6.0",
        "3.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GENEALOGICAL-TREE-XSS-CWE-79",
      "plugin_slug": "genealogical-tree",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GENESIS-CLUB-LITE-XSS-CVE-2025-57993",
      "plugin_slug": "genesis-club-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-57993",
      "affected_versions": [
        "1.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57993",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GETPAID-WALLET-SQLI-CWE-89",
      "plugin_slug": "getpaid-wallet",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-GETPAID-WALLET-SQLI-CWE-89",
      "plugin_slug": "getpaid-wallet",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-GETRESPONSE-CSRF-CVE-2025-58266",
      "plugin_slug": "getresponse",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-58266",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58266",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GETRESPONSE-KNOWN-CVE-CVE-2025-58266",
      "plugin_slug": "getresponse",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-58266",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58266",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GETRESPONSE-SQLI-CVE-2025-58266",
      "plugin_slug": "getresponse",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-58266",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58266",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GETRESPONSE-SQLI-CVE-2025-58266",
      "plugin_slug": "getresponse",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-58266",
      "affected_versions": [
        "2.6.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58266",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GIFT-MESSAGE-FOR-WOOCOMMERCE-XSS-CVE-2025-30521",
      "plugin_slug": "gift-message-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-30521",
      "affected_versions": [
        "1.7.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30521",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GIVE-XSS-CVE-2025-57884",
      "plugin_slug": "give",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-57884",
      "affected_versions": [
        "4.16.3",
        "4.16.5",
        "4.16.5.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 181,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57884",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GIVEASAP-XSS-CVE-2025-47684",
      "plugin_slug": "giveasap",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47684",
      "affected_versions": [
        "2.50.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47684",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GLS-SHIPPING-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "gls-shipping-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GMAP-EMBED-XSS-CVE-2025-24579",
      "plugin_slug": "gmap-embed",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24579",
      "affected_versions": [
        "1.9.6",
        "1.9.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24579",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GOAL-TRACKER-FOR-PATREON-XSS-CVE-2025-48313",
      "plugin_slug": "goal-tracker-for-patreon",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48313",
      "affected_versions": [
        "0.4.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48313",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-BROKEN-ACCESS-CONTROL-CVE-2022-4943",
      "plugin_slug": "google-authenticator",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2022-4943",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-4943",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-CSRF-CVE-2022-0229",
      "plugin_slug": "google-authenticator",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2022-0229",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-0229",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-CSRF-CVE-2022-0875",
      "plugin_slug": "google-authenticator",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2022-0875",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-0875",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-KNOWN-CVE-CVE-2022-44589",
      "plugin_slug": "google-authenticator",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "high",
      "cve": "CVE-2022-44589",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-44589",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-KNOWN-CVE-CVE-2022-42461",
      "plugin_slug": "google-authenticator",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "medium",
      "cve": "CVE-2022-42461",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-42461",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-AUTHENTICATOR-XSS-CVE-2022-1321",
      "plugin_slug": "google-authenticator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-1321",
      "affected_versions": [
        "0.55",
        "0.56"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-1321",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-CAPTCHA-SQLI-CWE-89",
      "plugin_slug": "google-captcha",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.87"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GOOGLE-CAPTCHA-SQLI-CWE-89",
      "plugin_slug": "google-captcha",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.87"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GOOGLE-SHORTLINK-SQLI-CWE-89",
      "plugin_slug": "google-shortlink",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GOOGLE-SHORTLINK-SQLI-CWE-89",
      "plugin_slug": "google-shortlink",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GOOGLE-SHORTLINK-XSS-CWE-79",
      "plugin_slug": "google-shortlink",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GOOGLE-TAG-MANAGER-XSS-CVE-2022-1707",
      "plugin_slug": "google-tag-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-1707",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-1707",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GOOGLE-TAG-MANAGER-XSS-CVE-2022-1961",
      "plugin_slug": "google-tag-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-1961",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-1961",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GORILLA-DEBUG-XSS-CWE-79",
      "plugin_slug": "gorilla-debug",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GOTMLS-XSS-CVE-2026-40771",
      "plugin_slug": "gotmls",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-40771",
      "affected_versions": [
        "4.23.90"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40771",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GPTRANSLATE-RCE-CVE-2026-49079",
      "plugin_slug": "gptranslate",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2026-49079",
      "affected_versions": [
        "2.33.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-49079",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-GPTRANSLATE-RCE-CVE-2026-49079",
      "plugin_slug": "gptranslate",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "cve": "CVE-2026-49079",
      "affected_versions": [
        "2.33.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-49079",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-GPTRANSLATE-XSS-CVE-2026-49079",
      "plugin_slug": "gptranslate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-49079",
      "affected_versions": [
        "2.33.6",
        "2.33.7",
        "2.33.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-49079",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GREEN-MONEY-PAYMENT-GATEWAY-XSS-CWE-79",
      "plugin_slug": "green-money-payment-gateway",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.7",
        "3.3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GREENSKEEPER-XSS-CWE-79",
      "plugin_slug": "greenskeeper",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-GRID-XSS-CWE-79",
      "plugin_slug": "grid",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GROOVY-MENU-FREE-XSS-CVE-2025-60173",
      "plugin_slug": "groovy-menu-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-60173",
      "affected_versions": [
        "1.4.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60173",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-BROKEN-ACCESS-CONTROL-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-CSRF-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-CSRF-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1",
        "2.7.11.11"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-KNOWN-CVE-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-SQLI-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-SSRF-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "4.5.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-SSRF-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "4.5.11"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-XSS-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1",
        "2.7.11.11",
        "4.5.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GROUNDHOGG-XSS-CVE-2025-11762",
      "plugin_slug": "groundhogg",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-11762",
      "affected_versions": [
        "2.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11762",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-GS-TESTIMONIAL-XSS-CWE-79",
      "plugin_slug": "gs-testimonial",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GSHEETCONNECTOR-EASY-DIGITAL-DOWNLOADS-XSS-CWE-79",
      "plugin_slug": "gsheetconnector-easy-digital-downloads",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GSPEECH-XSS-CVE-2025-10045",
      "plugin_slug": "gspeech",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-10045",
      "affected_versions": [
        "3.21.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10045",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-GT3-PHOTO-VIDEO-GALLERY-XSS-CVE-2025-68889",
      "plugin_slug": "gt3-photo-video-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68889",
      "affected_versions": [
        "2.7.7.29"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68889",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GTBABEL-XSS-CWE-79",
      "plugin_slug": "gtbabel",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.8.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-GWOLLE-GB-XSS-CWE-79",
      "plugin_slug": "gwolle-gb",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-GYTA-BUYBACK-XSS-CWE-79",
      "plugin_slug": "gyta-buyback",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-HAFENSTUDIOS-ADS-XSS-CWE-79",
      "plugin_slug": "hafenstudios-ads",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.7",
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-HAPPY-HELPDESK-SUPPORT-TICKET-SYSTEM-XSS-CVE-2025-48362",
      "plugin_slug": "happy-helpdesk-support-ticket-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48362",
      "affected_versions": [
        "1.0.12"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48362",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HAPPYFORMS-XSS-CVE-2024-52492",
      "plugin_slug": "happyforms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-52492",
      "affected_versions": [
        "1.26.14",
        "1.26.15"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-52492",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-HEALTH-CHECK-SSRF-CWE-918",
      "plugin_slug": "health-check",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HEALTH-CHECK-SSRF-CWE-918",
      "plugin_slug": "health-check",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HEZARFEN-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "hezarfen-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.14.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-HIDE-ADMIN-BAR-BASED-ON-USER-ROLES-XSS-CWE-79",
      "plugin_slug": "hide-admin-bar-based-on-user-roles",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.2.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-HIDE-REAL-DOWNLOAD-PATH-XSS-CWE-79",
      "plugin_slug": "hide-real-download-path",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HIDE-SHIPPING-METHOD-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "hide-shipping-method-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HIGHLIGHT-KNOWN-CVE-CVE-2023-33187",
      "plugin_slug": "highlight",
      "vuln_class": "known-cve",
      "cwe": "CWE-319",
      "severity": "medium",
      "cve": "CVE-2023-33187",
      "affected_versions": [
        "2.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-33187",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HITSTEPS-VISITOR-MANAGER-XSS-CWE-79",
      "plugin_slug": "hitsteps-visitor-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.94"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-HM-COOL-AUTHOR-BOX-WIDGET-XSS-CWE-79",
      "plugin_slug": "hm-cool-author-box-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HOEBOE-XSS-CWE-79",
      "plugin_slug": "hoeboe",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-HOMEY-BROKEN-ACCESS-CONTROL-CVE-2025-46458",
      "plugin_slug": "homey",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-46458",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46458",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HOMEY-KNOWN-CVE-CVE-2025-46458",
      "plugin_slug": "homey",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2025-46458",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46458",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HOUZEZ-PROPERTY-FEED-SSRF-CVE-2025-30882",
      "plugin_slug": "houzez-property-feed",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-30882",
      "affected_versions": [
        "2.5.47",
        "2.5.48",
        "2.5.49"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30882",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-HOUZEZ-PROPERTY-FEED-SSRF-CVE-2025-30882",
      "plugin_slug": "houzez-property-feed",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-30882",
      "affected_versions": [
        "2.5.47",
        "2.5.48",
        "2.5.49"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30882",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-HT-CONTACTFORM-XSS-CVE-2025-24542",
      "plugin_slug": "ht-contactform",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24542",
      "affected_versions": [
        "2.9.2",
        "2.9.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24542",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-HTML5-LYRICS-KARAOKE-PLAYER-SQLI-CWE-89",
      "plugin_slug": "html5-lyrics-karaoke-player",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HTML5-LYRICS-KARAOKE-PLAYER-SQLI-CWE-89",
      "plugin_slug": "html5-lyrics-karaoke-player",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HTML5-LYRICS-KARAOKE-PLAYER-XSS-CWE-79",
      "plugin_slug": "html5-lyrics-karaoke-player",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HTML5-VIDEO-PLAYER-WITH-PLAYLIST-SQLI-CWE-89",
      "plugin_slug": "html5-video-player-with-playlist",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.50"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HTML5-VIDEO-PLAYER-WITH-PLAYLIST-SQLI-CWE-89",
      "plugin_slug": "html5-video-player-with-playlist",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.50"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HTML5-VIDEO-PLAYER-WITH-PLAYLIST-XSS-CWE-79",
      "plugin_slug": "html5-video-player-with-playlist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.50"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HURRAKIFY-XSS-CWE-79",
      "plugin_slug": "hurrakify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-HXFE-CODE-FIRST-FORMS-XSS-CWE-79",
      "plugin_slug": "hxfe-code-first-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.5",
        "1.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 46,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-I3GEEK-BAIDUXZH-XSS-CVE-2025-48154",
      "plugin_slug": "i3geek-baiduxzh",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48154",
      "affected_versions": [
        "1.4.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48154",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IBTANA-ECOMMERCE-PRODUCT-ADDONS-SQLI-CVE-2025-58602",
      "plugin_slug": "ibtana-ecommerce-product-addons",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-58602",
      "affected_versions": [
        "0.4.7.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58602",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IBTANA-ECOMMERCE-PRODUCT-ADDONS-SQLI-CVE-2025-58602",
      "plugin_slug": "ibtana-ecommerce-product-addons",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-58602",
      "affected_versions": [
        "0.4.7.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58602",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ICAL-FEEDS-XSS-CWE-79",
      "plugin_slug": "ical-feeds",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ICDSOFT-RESELLER-STORE-XSS-CVE-2024-54266",
      "plugin_slug": "icdsoft-reseller-store",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54266",
      "affected_versions": [
        "2.6.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54266",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ICEGRAM-RAINMAKER-SSRF-CWE-918",
      "plugin_slug": "icegram-rainmaker",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.3.21"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ICEGRAM-RAINMAKER-SSRF-CWE-918",
      "plugin_slug": "icegram-rainmaker",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.3.21"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IDEAPUSH-XSS-CWE-79",
      "plugin_slug": "ideapush",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.77"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IDONATE-BROKEN-ACCESS-CONTROL-CVE-2025-32627",
      "plugin_slug": "idonate",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-32627",
      "affected_versions": [
        "2.0.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32627",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-IDONATE-CSRF-CVE-2025-32627",
      "plugin_slug": "idonate",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-32627",
      "affected_versions": [
        "2.0.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32627",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-IDONATE-KNOWN-CVE-CVE-2025-32627",
      "plugin_slug": "idonate",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-32627",
      "affected_versions": [
        "2.0.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32627",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-IDONATE-LFI-CVE-2025-32627",
      "plugin_slug": "idonate",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2025-32627",
      "affected_versions": [
        "2.0.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32627",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-IF-AS-SHORTCODE-XSS-CVE-2025-68562",
      "plugin_slug": "if-as-shortcode",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68562",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68562",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IF-SO-XSS-CVE-2025-58631",
      "plugin_slug": "if-so",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58631",
      "affected_versions": [
        "1.10",
        "1.10.0.1",
        "1.9.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58631",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IGNITIONDECK-SSRF-CVE-2025-58986",
      "plugin_slug": "ignitiondeck",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-58986",
      "affected_versions": [
        "2.0.17",
        "2.0.18"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58986",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IGNITIONDECK-SSRF-CVE-2025-58986",
      "plugin_slug": "ignitiondeck",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-58986",
      "affected_versions": [
        "2.0.17",
        "2.0.18"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58986",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IKS-MENU-XSS-CWE-79",
      "plugin_slug": "iks-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.12.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMAGE-EDITOR-BY-PIXO-XSS-CWE-79",
      "plugin_slug": "image-editor-by-pixo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.10",
        "2.3.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMAGE-META-SAVE-SQLI-CWE-89",
      "plugin_slug": "image-meta-save",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMAGE-META-SAVE-SQLI-CWE-89",
      "plugin_slug": "image-meta-save",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2021-26235",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-476",
      "severity": "high",
      "cve": "CVE-2021-26235",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-26235",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2022-36947",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-787",
      "severity": "critical",
      "cve": "CVE-2022-36947",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-36947",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2021-26233",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-787",
      "severity": "high",
      "cve": "CVE-2021-26233",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-26233",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2021-26234",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-787",
      "severity": "high",
      "cve": "CVE-2021-26234",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-26234",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2021-26236",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-787",
      "severity": "high",
      "cve": "CVE-2021-26236",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-26236",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMAGE-VIEWER-KNOWN-CVE-CVE-2021-26237",
      "plugin_slug": "image-viewer",
      "vuln_class": "known-cve",
      "cwe": "CWE-787",
      "severity": "high",
      "cve": "CVE-2021-26237",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-26237",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMONEY-XSS-CVE-2025-68495",
      "plugin_slug": "imoney",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68495",
      "affected_versions": [
        "0.36 (01-08-2012)"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68495",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IMPORT-EVENTBRITE-EVENTS-XSS-CWE-79",
      "plugin_slug": "import-eventbrite-events",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMPORT-EXPORT-MENU-XSS-CWE-79",
      "plugin_slug": "import-export-menu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IMPORT-USERS-FROM-CSV-WITH-META-XSS-CWE-79",
      "plugin_slug": "import-users-from-csv-with-meta",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.1",
        "2.4.2",
        "2.4.3",
        "2.4.4",
        "2.4.5",
        "2.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-IN-MEMORIAM-LIGHT-A-CANDLE-XSS-CWE-79",
      "plugin_slug": "in-memoriam-light-a-candle",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INDEPENDENT-ANALYTICS-XSS-CWE-79",
      "plugin_slug": "independent-analytics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.14.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INFILITY-GLOBAL-SQLI-CVE-2026-39611",
      "plugin_slug": "infility-global",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-39611",
      "affected_versions": [
        "2.15.28",
        "2.15.29",
        "2.15.30",
        "2.15.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFILITY-GLOBAL-SQLI-CVE-2026-39611",
      "plugin_slug": "infility-global",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-39611",
      "affected_versions": [
        "2.15.28",
        "2.15.29",
        "2.15.30",
        "2.15.32"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFILITY-GLOBAL-SSRF-CVE-2026-39611",
      "plugin_slug": "infility-global",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-39611",
      "affected_versions": [
        "2.15.28",
        "2.15.29",
        "2.15.30",
        "2.15.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFILITY-GLOBAL-SSRF-CVE-2026-39611",
      "plugin_slug": "infility-global",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-39611",
      "affected_versions": [
        "2.15.28",
        "2.15.29",
        "2.15.30",
        "2.15.32"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFILITY-GLOBAL-XSS-CVE-2026-39611",
      "plugin_slug": "infility-global",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39611",
      "affected_versions": [
        "2.15.28",
        "2.15.29",
        "2.15.30",
        "2.15.32"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 195,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFOCOB-TRACKING-XSS-CWE-79",
      "plugin_slug": "infocob-tracking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INFUSIONSOFT-OFFICIAL-OPT-IN-FORMS-XSS-CWE-79",
      "plugin_slug": "infusionsoft-official-opt-in-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INPOST-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "inpost-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.2",
        "1.9.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INSERT-HEADERS-AND-FOOTERS-XSS-CVE-2026-42748",
      "plugin_slug": "insert-headers-and-footers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-42748",
      "affected_versions": [
        "2.3.7",
        "2.3.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 30,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-42748",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INSERT-OR-EMBED-ARTICULATE-CONTENT-INTO-WORDPRESS-XSS-CWE-79",
      "plugin_slug": "insert-or-embed-articulate-content-into-wordpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3000000027"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INSTAGRAM-SLIDER-WIDGET-XSS-CVE-2026-5231",
      "plugin_slug": "instagram-slider-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-5231",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-5231",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INSTANT-KNOWN-CVE-CVE-2017-13099",
      "plugin_slug": "instant",
      "vuln_class": "known-cve",
      "cwe": "CWE-203",
      "severity": "high",
      "cve": "CVE-2017-13099",
      "affected_versions": [
        "3.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2017-13099",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-INSTARANK-SQLI-CWE-89",
      "plugin_slug": "instarank",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0.10",
        "2.0.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-INSTARANK-SQLI-CWE-89",
      "plugin_slug": "instarank",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0.10",
        "2.0.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-INSTAWP-CONNECT-XSS-CVE-2025-32209",
      "plugin_slug": "instawp-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32209",
      "affected_versions": [
        "0.1.3.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32209",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-INTEGRATION-DYNAMICS-XSS-CWE-79",
      "plugin_slug": "integration-dynamics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INTEGRATION-OF-ZOHO-BOOKS-AND-WC-XSS-CWE-79",
      "plugin_slug": "integration-of-zoho-books-and-wc",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-INTERACTIVE-REAL-ESTATE-XSS-CWE-79",
      "plugin_slug": "interactive-real-estate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.5.0",
        "2.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-INTERVIEW-SQLI-CVE-2025-31640",
      "plugin_slug": "interview",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-31640",
      "affected_versions": [
        "1.01"
      ],
      "source": "cve",
      "engines": [
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31640",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INVELITY-SPS-CONNECT-XSS-CVE-2025-69085",
      "plugin_slug": "invelity-sps-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69085",
      "affected_versions": [
        "1.0.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69085",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-INVOICE-GATEWAY-YESHINVOICE-XSS-CWE-79",
      "plugin_slug": "invoice-gateway-yeshinvoice",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-INVOICE-PAYMENT-GATEWAY-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "invoice-payment-gateway-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-INVUM-POS-XSS-CWE-79",
      "plugin_slug": "invum-pos",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-IP-BLOCKER-LITE-CSRF-CVE-2023-23993",
      "plugin_slug": "ip-blocker-lite",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2023-23993",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-23993",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-IP-LOCATION-BLOCK-XSS-CWE-79",
      "plugin_slug": "ip-location-block",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IPQUALITYSCORE-FRAUD-DETECTION-XSS-CWE-79",
      "plugin_slug": "ipqualityscore-fraud-detection",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.83"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-IPSENTRY-SECURITY-XSS-CWE-79",
      "plugin_slug": "ipsentry-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.10.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-IROBOTSTXT-SEO-XSS-CWE-79",
      "plugin_slug": "irobotstxt-seo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ISAPE-XSS-CVE-2025-68856",
      "plugin_slug": "isape",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68856",
      "affected_versions": [
        "0.72 (02-05-2010)"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68856",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JETPACK-BACKUP-SSRF-CWE-918",
      "plugin_slug": "jetpack-backup",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JETPACK-BACKUP-SSRF-CWE-918",
      "plugin_slug": "jetpack-backup",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-JETPACK-BACKUP-XSS-CWE-79",
      "plugin_slug": "jetpack-backup",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-JETPACK-SEARCH-SSRF-CWE-918",
      "plugin_slug": "jetpack-search",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "7.0.0",
        "7.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JETPACK-SEARCH-SSRF-CWE-918",
      "plugin_slug": "jetpack-search",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "7.0.0",
        "7.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JETPACK-SEARCH-XSS-CWE-79",
      "plugin_slug": "jetpack-search",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.0.0",
        "7.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JETPACK-SOCIAL-SSRF-CWE-918",
      "plugin_slug": "jetpack-social",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "9.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-JETPACK-SOCIAL-SSRF-CWE-918",
      "plugin_slug": "jetpack-social",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "9.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-JETPACK-SOCIAL-XSS-CWE-79",
      "plugin_slug": "jetpack-social",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-JETPACK-VIDEOPRESS-SSRF-CWE-918",
      "plugin_slug": "jetpack-videopress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JETPACK-VIDEOPRESS-SSRF-CWE-918",
      "plugin_slug": "jetpack-videopress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JETPACK-VIDEOPRESS-XSS-CWE-79",
      "plugin_slug": "jetpack-videopress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JF3-MAINTENANCE-MODE-XSS-CWE-79",
      "plugin_slug": "jf3-maintenance-mode",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JOBWP-XSS-CVE-2025-67943",
      "plugin_slug": "jobwp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67943",
      "affected_versions": [
        "2.4.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67943",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JOLI-TABLE-OF-CONTENTS-XSS-CWE-79",
      "plugin_slug": "joli-table-of-contents",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-JS-JOBS-SQLI-CVE-2025-32572",
      "plugin_slug": "js-jobs",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-32572",
      "affected_versions": [
        "1.1.1",
        "1.1.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32572",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-JS-JOBS-SQLI-CVE-2025-32572",
      "plugin_slug": "js-jobs",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2025-32572",
      "affected_versions": [
        "1.1.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32572",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-JS-JOBS-XSS-CVE-2025-32572",
      "plugin_slug": "js-jobs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-32572",
      "affected_versions": [
        "1.1.1",
        "1.1.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32572",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-JUPITERX-CORE-RCE-CVE-2025-47557",
      "plugin_slug": "jupiterx-core",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2025-47557",
      "affected_versions": [
        "4.50.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47557",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JUPITERX-CORE-RCE-CVE-2025-47557",
      "plugin_slug": "jupiterx-core",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "cve": "CVE-2025-47557",
      "affected_versions": [
        "4.50.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47557",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-JUPITERX-CORE-XSS-CVE-2025-47557",
      "plugin_slug": "jupiterx-core",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47557",
      "affected_versions": [
        "4.50.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47557",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KAKAO-TAM-XSS-CWE-79",
      "plugin_slug": "kakao-tam",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-KAMA-CLIC-COUNTER-SQLI-CWE-89",
      "plugin_slug": "kama-clic-counter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-KAMA-CLIC-COUNTER-SQLI-CWE-89",
      "plugin_slug": "kama-clic-counter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-KANPRESS-XSS-CVE-2025-62887",
      "plugin_slug": "kanpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62887",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62887",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KATA-PLUS-SSRF-CWE-918",
      "plugin_slug": "kata-plus",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KATA-PLUS-SSRF-CWE-918",
      "plugin_slug": "kata-plus",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KATA-PLUS-XSS-CVE-2025-32486",
      "plugin_slug": "kata-plus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-32486",
      "affected_versions": [
        "1.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32486",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-KENTA-COMPANION-XSS-CVE-2025-14999",
      "plugin_slug": "kenta-companion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-14999",
      "affected_versions": [
        "1.3.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14999",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KENTO-SPLASH-SCREEN-XSS-CVE-2025-53319",
      "plugin_slug": "kento-splash-screen",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53319",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53319",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KERK-EN-IT-PARISH-XSS-CWE-79",
      "plugin_slug": "kerk-en-it-parish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-KK-STAR-RATINGS-XSS-CVE-2024-11733",
      "plugin_slug": "kk-star-ratings",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11733",
      "affected_versions": [
        "5.4.10.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11733",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-KNS-DYNAMIC-DISCOUNTS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "kns-dynamic-discounts-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-KONTACKT-MEDIAPILOT-SSRF-CWE-918",
      "plugin_slug": "kontackt-mediapilot",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "0.9.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-KONTACKT-MEDIAPILOT-SSRF-CWE-918",
      "plugin_slug": "kontackt-mediapilot",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "0.9.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LANGFORGE-XSS-CWE-79",
      "plugin_slug": "langforge",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.24",
        "1.0.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-LEAD-FORM-BUILDER-XSS-CVE-2026-32573",
      "plugin_slug": "lead-form-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-32573",
      "affected_versions": [
        "2.2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-32573",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LEAN-CART-SHARE-AND-SAVE-XSS-CWE-79",
      "plugin_slug": "lean-cart-share-and-save",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.1",
        "1.1.3",
        "1.1.4",
        "1.1.5",
        "1.1.6",
        "1.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 74,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LEARNING-MANAGEMENT-SYSTEM-KNOWN-CVE-CVE-2026-2519",
      "plugin_slug": "learning-management-system",
      "vuln_class": "known-cve",
      "cwe": "CWE-538",
      "severity": "medium",
      "cve": "CVE-2026-2519",
      "affected_versions": [
        "2.3.1",
        "2.3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-2519",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LEARNING-MANAGEMENT-SYSTEM-KNOWN-CVE-CVE-2026-2519",
      "plugin_slug": "learning-management-system",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2026-2519",
      "affected_versions": [
        "2.3.1",
        "2.3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-2519",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LEARNPRESS-BROKEN-ACCESS-CONTROL-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-BROKEN-ACCESS-CONTROL-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-285",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-BROKEN-ACCESS-CONTROL-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-BROKEN-ACCESS-CONTROL-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-CSRF-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-CSRF-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-DESERIALIZATION-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-FILE-UPLOAD-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-FILE-UPLOAD-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-327",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-420",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-80",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-KNOWN-CVE-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "known-cve",
      "cwe": "CWE-88",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-LFI-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-SQLI-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-SQLI-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-XSS-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEARNPRESS-XSS-CVE-2026-39598",
      "plugin_slug": "learnpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-39598",
      "affected_versions": [
        "3.2.8.8"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 12,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39598",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-LEYKA-XSS-CWE-79",
      "plugin_slug": "leyka",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.32.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LIBRARY-MANAGEMENT-SYSTEM-XSS-CVE-2025-24577",
      "plugin_slug": "library-management-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-24577",
      "affected_versions": [
        "3.5.8",
        "3.5.9",
        "3.6",
        "3.6.1",
        "3.6.2",
        "3.6.3",
        "3.6.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 7,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24577",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LIBRARY-MANAGEMENT-SYSTEM-XSS-CVE-2025-9755",
      "plugin_slug": "library-management-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-9755",
      "affected_versions": [
        "3.6.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9755",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-LIKEBTN-LIKE-BUTTON-XSS-CWE-79",
      "plugin_slug": "likebtn-like-button",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.60"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LIKERT-SURVEY-MASTER-XSS-CVE-2025-9882",
      "plugin_slug": "likert-survey-master",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-9882",
      "affected_versions": [
        "0.8.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9882",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LINGUISE-SSRF-CWE-918",
      "plugin_slug": "linguise",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.2.57",
        "2.2.58",
        "2.2.59"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LINGUISE-SSRF-CWE-918",
      "plugin_slug": "linguise",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.2.57",
        "2.2.58",
        "2.2.59"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LINK-LIBRARY-XSS-CWE-79",
      "plugin_slug": "link-library",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.9.2",
        "7.9.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 441,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LINKEDIN-AUTO-PUBLISH-XSS-CWE-79",
      "plugin_slug": "linkedin-auto-publish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LIVE-SPORTS-STREAMTHUNDER-SQLI-CWE-89",
      "plugin_slug": "live-sports-streamthunder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LIVE-SPORTS-STREAMTHUNDER-SQLI-CWE-89",
      "plugin_slug": "live-sports-streamthunder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LIVELANG-XSS-CWE-79",
      "plugin_slug": "livelang",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.2",
        "2.1.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LIZA-SPOTIFY-WIDGET-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "liza-spotify-widget-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LLMAGNET-LLM-TXT-GENERATOR-XSS-CWE-79",
      "plugin_slug": "llmagnet-llm-txt-generator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.2",
        "3.4.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 44,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LOCAL-MAGIC-SQLI-CVE-2025-2789",
      "plugin_slug": "local-magic",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-2789",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOCAL-MAGIC-SQLI-CVE-2025-2789",
      "plugin_slug": "local-magic",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-2789",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOCAL-MAGIC-SSRF-CVE-2025-2789",
      "plugin_slug": "local-magic",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-2789",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOCAL-MAGIC-SSRF-CVE-2025-2789",
      "plugin_slug": "local-magic",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-2789",
      "affected_versions": [
        "2.9.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2789",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOCAL-PICKUP-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "local-pickup-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LOCAL-SYNC-XSS-CVE-2026-1756",
      "plugin_slug": "local-sync",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1756",
      "affected_versions": [
        "1.1.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1756",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOCATION-WEATHER-XSS-CWE-79",
      "plugin_slug": "location-weather",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.6",
        "3.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOGIFY-XSS-CWE-79",
      "plugin_slug": "logify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-LOGIN-CUSTOMIZER-XSS-CVE-2025-14736",
      "plugin_slug": "login-customizer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-14736",
      "affected_versions": [
        "2.5.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14736",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOGIN-DESIGNER-XSS-CWE-79",
      "plugin_slug": "login-designer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-LOGIN-PAGE-STYLER-XSS-CWE-79",
      "plugin_slug": "login-page-styler",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOGIN-WITH-AJAX-XSS-CWE-79",
      "plugin_slug": "login-with-ajax",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LOGO-SHOWCASE-ULTIMATE-XSS-CWE-79",
      "plugin_slug": "logo-showcase-ultimate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LOGO-SHOWCASE-WITH-SLICK-SLIDER-XSS-CWE-79",
      "plugin_slug": "logo-showcase-with-slick-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LPAGERY-XSS-CVE-2026-0674",
      "plugin_slug": "lpagery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-0674",
      "affected_versions": [
        "2.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0674",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-FEDEX-FREIGHT-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-fedex-freight-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.4.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-FEDEX-FREIGHT-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-fedex-freight-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.4.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-FREIGHTVIEW-EDITION-XSS-CWE-79",
      "plugin_slug": "ltl-freight-quotes-freightview-edition",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-ODFL-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-odfl-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-ODFL-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-odfl-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-TQL-EDITION-XSS-CVE-2025-58642",
      "plugin_slug": "ltl-freight-quotes-tql-edition",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58642",
      "affected_versions": [
        "1.2.12"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58642",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-UPS-EDITION-SQLI-CVE-2024-13491",
      "plugin_slug": "ltl-freight-quotes-ups-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-13491",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13491",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-UPS-EDITION-SQLI-CVE-2024-13491",
      "plugin_slug": "ltl-freight-quotes-ups-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-13491",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13491",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-XPO-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-xpo-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.3.17"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LTL-FREIGHT-QUOTES-XPO-EDITION-SQLI-CWE-89",
      "plugin_slug": "ltl-freight-quotes-xpo-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.3.17"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LUCKYWP-SCRIPTS-CONTROL-XSS-CWE-79",
      "plugin_slug": "luckywp-scripts-control",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LUCKYWP-TABLE-OF-CONTENTS-XSS-CWE-79",
      "plugin_slug": "luckywp-table-of-contents",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-LWS-OPTIMIZE-SSRF-CWE-918",
      "plugin_slug": "lws-optimize",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-LWS-OPTIMIZE-SSRF-CWE-918",
      "plugin_slug": "lws-optimize",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-M-CHART-XSS-CWE-79",
      "plugin_slug": "m-chart",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.1",
        "2.2.2",
        "2.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAGE-EVENTPRESS-XSS-CVE-2024-13807",
      "plugin_slug": "mage-eventpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13807",
      "affected_versions": [
        "5.3.5",
        "5.3.6",
        "5.3.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 62,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13807",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MAGIC-CONVERSATION-FOR-GRAVITY-FORMS-XSS-CVE-2026-34897",
      "plugin_slug": "magic-conversation-for-gravity-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-34897",
      "affected_versions": [
        "3.0.101"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-34897",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAGIC-LINK-XSS-CWE-79",
      "plugin_slug": "magic-link",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.0",
        "2.2.0",
        "2.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 45,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAGIC-LOGIN-API-XSS-CWE-79",
      "plugin_slug": "magic-login-api",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAGIC-POST-THUMBNAIL-XSS-CWE-79",
      "plugin_slug": "magic-post-thumbnail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-MAIL-BABY-SMTP-SQLI-CVE-2025-59577",
      "plugin_slug": "mail-baby-smtp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-59577",
      "affected_versions": [
        "3.2.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-59577",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAIL-BABY-SMTP-SQLI-CVE-2025-59577",
      "plugin_slug": "mail-baby-smtp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-59577",
      "affected_versions": [
        "3.2.13"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-59577",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAIL-INTEGRATION-365-XSS-CWE-79",
      "plugin_slug": "mail-integration-365",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAILCHIMP-BROKEN-ACCESS-CONTROL-CVE-2023-51682",
      "plugin_slug": "mailchimp",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2023-51682",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-51682",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILCHIMP-KNOWN-CVE-CVE-2024-8680",
      "plugin_slug": "mailchimp",
      "vuln_class": "known-cve",
      "cwe": "CWE-80",
      "severity": "medium",
      "cve": "CVE-2024-8680",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8680",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILCHIMP-OPEN-REDIRECT-CVE-2023-32517",
      "plugin_slug": "mailchimp",
      "vuln_class": "open-redirect",
      "cwe": "CWE-601",
      "severity": "medium",
      "cve": "CVE-2023-32517",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-32517",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILCHIMP-SUBSCRIBE-SM-SSRF-CWE-918",
      "plugin_slug": "mailchimp-subscribe-sm",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILCHIMP-SUBSCRIBE-SM-SSRF-CWE-918",
      "plugin_slug": "mailchimp-subscribe-sm",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILCHIMP-SUBSCRIBE-SM-XSS-CWE-79",
      "plugin_slug": "mailchimp-subscribe-sm",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MAILSTER-XSS-CVE-2025-12521",
      "plugin_slug": "mailster",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12521",
      "affected_versions": [
        "2.0.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12521",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MAINWP-CHILD-SSRF-CVE-2024-10111",
      "plugin_slug": "mainwp-child",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2024-10111",
      "affected_versions": [
        "6.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10111",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAINWP-CHILD-SSRF-CVE-2024-10111",
      "plugin_slug": "mainwp-child",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2024-10111",
      "affected_versions": [
        "6.1.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 42,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10111",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAINWP-CHILD-XSS-CVE-2024-10111",
      "plugin_slug": "mainwp-child",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-10111",
      "affected_versions": [
        "6.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10111",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAMURJOR-INVOICE-SQLI-CWE-89",
      "plugin_slug": "mamurjor-invoice",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAMURJOR-INVOICE-SQLI-CWE-89",
      "plugin_slug": "mamurjor-invoice",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAMURJOR-SIMPLE-CONTACT-FORM-SQLI-CWE-89",
      "plugin_slug": "mamurjor-simple-contact-form",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MAMURJOR-SIMPLE-CONTACT-FORM-SQLI-CWE-89",
      "plugin_slug": "mamurjor-simple-contact-form",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MANAGE-FOLDERS-AND-LABELS-GRAVITY-FORMS-SQLI-CWE-89",
      "plugin_slug": "manage-folders-and-labels-gravity-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-MANAGE-FOLDERS-AND-LABELS-GRAVITY-FORMS-SQLI-CWE-89",
      "plugin_slug": "manage-folders-and-labels-gravity-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-MANAGE-FOLDERS-AND-LABELS-GRAVITY-FORMS-XSS-CWE-79",
      "plugin_slug": "manage-folders-and-labels-gravity-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.6",
        "1.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-MANUAL-IMAGE-CROP-XSS-CWE-79",
      "plugin_slug": "manual-image-crop",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MANUALL-DOFOLLOW-XSS-CVE-2025-49948",
      "plugin_slug": "manuall-dofollow",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49948",
      "affected_versions": [
        "1.8.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49948",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MARKETING-AUTOMATION-SQLI-CVE-2025-26563",
      "plugin_slug": "marketing-automation",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-26563",
      "affected_versions": [
        "1.2.6.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-26563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MASJIDOS-XSS-CWE-79",
      "plugin_slug": "masjidos",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-MASS-EMAIL-TO-USERS-XSS-CWE-79",
      "plugin_slug": "mass-email-to-users",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MATRIMONY-SQLI-CVE-2022-26628",
      "plugin_slug": "matrimony",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2022-26628",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-26628",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEDIA-DOWNLOAD-XSS-CVE-2025-64382",
      "plugin_slug": "media-download",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-64382",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-64382",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MEDIA-FOLDER-XSS-CVE-2025-31072",
      "plugin_slug": "media-folder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31072",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31072",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MEDIA-LIBRARY-ASSISTANT-XSS-CVE-2026-1865",
      "plugin_slug": "media-library-assistant",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1865",
      "affected_versions": [
        "3.38",
        "3.39"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 75,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1865",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MEDIAPILOT-AI-XSS-CWE-79",
      "plugin_slug": "mediapilot-ai",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-MEDIAPRESS-XSS-CWE-79",
      "plugin_slug": "mediapress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MEKS-VIDEO-IMPORTER-XSS-CWE-79",
      "plugin_slug": "meks-video-importer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MELAPRESS-LOGIN-SECURITY-XSS-CVE-2024-13820",
      "plugin_slug": "melapress-login-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13820",
      "affected_versions": [
        "2.3.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13820",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MELIPAYAMAK-SQLI-CWE-89",
      "plugin_slug": "melipayamak",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.2.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MELIPAYAMAK-SQLI-CWE-89",
      "plugin_slug": "melipayamak",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.2.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MELIPAYAMAK-XSS-CWE-79",
      "plugin_slug": "melipayamak",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MEMBERHUB-XSS-CWE-79",
      "plugin_slug": "memberhub",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.28",
        "1.0.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-MEMBERS-BROKEN-ACCESS-CONTROL-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "medium",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-BROKEN-ACCESS-CONTROL-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MEMBERS-KNOWN-CVE-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-KNOWN-CVE-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "known-cve",
      "severity": "low",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-KNOWN-CVE-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-KNOWN-CVE-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "medium",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-KNOWN-CVE-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "known-cve",
      "cwe": "CWE-561",
      "severity": "medium",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MEMBERS-LFI-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "high",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MEMBERS-LFI-CVE-2026-57375",
      "plugin_slug": "members",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "medium",
      "cve": "CVE-2026-57375",
      "affected_versions": [
        "3.2.24",
        "3.2.25",
        "3.2.26"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57375",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MESA-MESA-RESERVATION-WIDGET-XSS-CVE-2025-49412",
      "plugin_slug": "mesa-mesa-reservation-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49412",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49412",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-METASYNC-SSRF-CVE-2026-0844",
      "plugin_slug": "metasync",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-0844",
      "affected_versions": [
        "2.6.18",
        "2.6.20"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0844",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-METASYNC-SSRF-CVE-2026-0844",
      "plugin_slug": "metasync",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-0844",
      "affected_versions": [
        "2.6.18",
        "2.6.20"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0844",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-METASYNC-XSS-CVE-2026-0844",
      "plugin_slug": "metasync",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-0844",
      "affected_versions": [
        "2.6.15",
        "2.6.16",
        "2.6.17",
        "2.6.18",
        "2.6.20"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 142,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0844",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-METFORM-XSS-CVE-2025-67954",
      "plugin_slug": "metform",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67954",
      "affected_versions": [
        "4.1.6",
        "4.1.7",
        "4.1.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67954",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MIGRATIK-XSS-CWE-79",
      "plugin_slug": "migratik",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.0",
        "1.3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 48,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-MIN-AND-MAX-QUANTITY-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "min-and-max-quantity-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MISSING-WIDGETS-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "missing-widgets-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MOBILE-PAGES-XSS-CWE-79",
      "plugin_slug": "mobile-pages",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MOMO-VENMO-XSS-CWE-79",
      "plugin_slug": "momo-venmo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MONITOR-ACTIVITIES-LOG-XSS-CWE-79",
      "plugin_slug": "monitor-activities-log",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MOOBERRY-BOOK-MANAGER-XSS-CWE-79",
      "plugin_slug": "mooberry-book-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.16.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MSTW-LEAGUE-MANAGER-XSS-CVE-2025-58794",
      "plugin_slug": "mstw-league-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58794",
      "affected_versions": [
        "2.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58794",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MT-ADDONS-FOR-ELEMENTOR-XSS-CVE-2024-12515",
      "plugin_slug": "mt-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12515",
      "affected_versions": [
        "1.1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12515",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MULTI-STEP-FORM-XSS-CVE-2025-22717",
      "plugin_slug": "multi-step-form",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22717",
      "affected_versions": [
        "1.7.27",
        "1.7.28"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22717",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MULTIPLE-FEATURED-IMAGES-XSS-CWE-79",
      "plugin_slug": "multiple-featured-images",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MUSIC-PLAYER-FOR-ELEMENTOR-XSS-CVE-2025-49067",
      "plugin_slug": "music-player-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49067",
      "affected_versions": [
        "2.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49067",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MY-FEED-SQLI-CWE-89",
      "plugin_slug": "my-feed",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MY-FEED-SQLI-CWE-89",
      "plugin_slug": "my-feed",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-MY-TICKETS-CSRF-CVE-2025-46230",
      "plugin_slug": "my-tickets",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-46230",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46230",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-MY-TICKETS-XSS-CVE-2025-46230",
      "plugin_slug": "my-tickets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-46230",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46230",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-MYCRED-SSRF-CVE-2026-39584",
      "plugin_slug": "mycred",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-39584",
      "affected_versions": [
        "3.2.0",
        "3.2.1",
        "3.2.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39584",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MYCRED-SSRF-CVE-2026-39584",
      "plugin_slug": "mycred",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-39584",
      "affected_versions": [
        "3.2.0",
        "3.2.1",
        "3.2.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39584",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MYCRED-XSS-CVE-2026-39584",
      "plugin_slug": "mycred",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39584",
      "affected_versions": [
        "3.2.0",
        "3.2.1",
        "3.2.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 78,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39584",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MYSHOUTS-SHOUTBOX-SQLI-CVE-2025-9883",
      "plugin_slug": "myshouts-shoutbox",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-9883",
      "affected_versions": [
        "0.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9883",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MYSHOUTS-SHOUTBOX-SQLI-CVE-2025-9883",
      "plugin_slug": "myshouts-shoutbox",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-9883",
      "affected_versions": [
        "0.9"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9883",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MYSTICKYELEMENTS-XSS-CVE-2025-12361",
      "plugin_slug": "mystickyelements",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12361",
      "affected_versions": [
        "2.3.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12361",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-MYSTICKYMENU-SQLI-CWE-89",
      "plugin_slug": "mystickymenu",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-MYSTICKYMENU-SQLI-CWE-89",
      "plugin_slug": "mystickymenu",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NAME-DIRECTORY-SQLI-CVE-2026-1841",
      "plugin_slug": "name-directory",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-1841",
      "affected_versions": [
        "1.33.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1841",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NAME-DIRECTORY-SQLI-CVE-2026-1841",
      "plugin_slug": "name-directory",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-1841",
      "affected_versions": [
        "1.33.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1841",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NAME-DIRECTORY-XSS-CVE-2026-1841",
      "plugin_slug": "name-directory",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1841",
      "affected_versions": [
        "1.33.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1841",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NELIO-AB-TESTING-RCE-CWE-95",
      "plugin_slug": "nelio-ab-testing",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "8.4.1",
        "8.5.0",
        "8.5.1",
        "8.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NELIO-AB-TESTING-RCE-CWE-95",
      "plugin_slug": "nelio-ab-testing",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "high",
      "affected_versions": [
        "8.4.1",
        "8.5.0",
        "8.5.1",
        "8.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEO-REPLACE-XSS-CWE-79",
      "plugin_slug": "neo-replace",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "26.7.20"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-NETPAY-CHECKOUT-XSS-CWE-79",
      "plugin_slug": "netpay-checkout",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.01.02"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NETREVIEWS-XSS-CWE-79",
      "plugin_slug": "netreviews",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NEW-USER-APPROVE-XSS-CWE-79",
      "plugin_slug": "new-user-approve",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NEWSLETTER-XSS-CWE-79",
      "plugin_slug": "newsletter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.3.0",
        "9.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-NEWSLETTER-PAGE-REDIRECTS-XSS-CVE-2024-49688",
      "plugin_slug": "newsletter-page-redirects",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-49688",
      "affected_versions": [
        "2.2.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-49688",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEWSLETTER-SUBSCRIPTION-WIDGET-FOR-SENDBLASTER-XSS-CVE-2025-53224",
      "plugin_slug": "newsletter-subscription-widget-for-sendblaster",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53224",
      "affected_versions": [
        "1.2.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53224",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEWSLETTERS-LITE-SSRF-CVE-2026-57668",
      "plugin_slug": "newsletters-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-57668",
      "affected_versions": [
        "4.15"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57668",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-NEWSLETTERS-LITE-SSRF-CVE-2026-54810",
      "plugin_slug": "newsletters-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-54810",
      "affected_versions": [
        "4.15"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEWSLETTERS-LITE-XSS-CVE-2026-54810",
      "plugin_slug": "newsletters-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-54810",
      "affected_versions": [
        "4.15"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 80,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEWSLETTERS-LITE-XSS-CVE-2026-57668",
      "plugin_slug": "newsletters-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-57668",
      "affected_versions": [
        "4.15"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57668",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-NEXTEND-FACEBOOK-CONNECT-XSS-CVE-2025-62993",
      "plugin_slug": "nextend-facebook-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62993",
      "affected_versions": [
        "3.1.25"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62993",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEXTGEN-GALLERY-SEARCH-GALLERIES-XSS-CWE-79",
      "plugin_slug": "nextgen-gallery-search-galleries",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NEXURA-SECURITY-XSS-CWE-79",
      "plugin_slug": "nexura-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0",
        "1.0.2",
        "1.0.4",
        "1.0.5",
        "1.0.6",
        "1.0.7",
        "1.0.8",
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 139,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NI-CRM-LEAD-SQLI-CVE-2024-53815",
      "plugin_slug": "ni-crm-lead",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-53815",
      "affected_versions": [
        "1.3.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53815",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NI-CRM-LEAD-SQLI-CVE-2024-53815",
      "plugin_slug": "ni-crm-lead",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-53815",
      "affected_versions": [
        "1.3.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53815",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NI-CRM-LEAD-XSS-CVE-2024-53815",
      "plugin_slug": "ni-crm-lead",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-53815",
      "affected_versions": [
        "1.3.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53815",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NI-WOOCOMMERCE-PRODUCT-EDITOR-XSS-CVE-2024-54231",
      "plugin_slug": "ni-woocommerce-product-editor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54231",
      "affected_versions": [
        "1.4.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54231",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NICHETABLE-XSS-CWE-79",
      "plugin_slug": "nichetable",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NINJA-ACCESSIBILITY-XSS-CWE-79",
      "plugin_slug": "ninja-accessibility",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-NINJA-DRIVE-XSS-CWE-79",
      "plugin_slug": "ninja-drive",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.1",
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NINJA-FORMS-XSS-CVE-2025-12980",
      "plugin_slug": "ninja-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12980",
      "affected_versions": [
        "3.14.10",
        "3.14.11",
        "3.14.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12980",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NINJAFIREWALL-XSS-CWE-79",
      "plugin_slug": "ninjafirewall",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.8.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-NINJASCANNER-SSRF-CVE-2025-7725",
      "plugin_slug": "ninjascanner",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-7725",
      "affected_versions": [
        "3.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-7725",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-NINJASCANNER-SSRF-CVE-2025-7725",
      "plugin_slug": "ninjascanner",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-7725",
      "affected_versions": [
        "3.3.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-7725",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-NODEWATCH-MONERO-XSS-CWE-79",
      "plugin_slug": "nodewatch-monero",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2",
        "1.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NON-LATIN-ATTACHMENTS-XSS-CWE-79",
      "plugin_slug": "non-latin-attachments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NONPROFIT-MANAGER-SSRF-CWE-918",
      "plugin_slug": "nonprofit-manager",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2026.07.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-NONPROFIT-MANAGER-SSRF-CWE-918",
      "plugin_slug": "nonprofit-manager",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2026.07.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-NOTIFAL-XSS-CWE-79",
      "plugin_slug": "notifal",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.3",
        "2.4.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NOTIFICATION-XSS-CWE-79",
      "plugin_slug": "notification",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-NOTIFICATION-FOR-TELEGRAM-XSS-CVE-2026-40787",
      "plugin_slug": "notification-for-telegram",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-40787",
      "affected_versions": [
        "3.5.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-40787",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NOTIFICATIONX-SSRF-CVE-2019-25297",
      "plugin_slug": "notificationx",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2019-25297",
      "affected_versions": [
        "3.2.12"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-25297",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-NOTIFICATIONX-SSRF-CVE-2019-25297",
      "plugin_slug": "notificationx",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2019-25297",
      "affected_versions": [
        "3.2.12"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-25297",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-NOVA-POSHTA-TTN-SQLI-CVE-2024-56284",
      "plugin_slug": "nova-poshta-ttn",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-56284",
      "affected_versions": [
        "1.19.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56284",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NOVA-POSHTA-TTN-SQLI-CVE-2024-56284",
      "plugin_slug": "nova-poshta-ttn",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-56284",
      "affected_versions": [
        "1.19.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56284",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NOVA-POSHTA-TTN-XSS-CVE-2024-56284",
      "plugin_slug": "nova-poshta-ttn",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56284",
      "affected_versions": [
        "1.19.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56284",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-NOWPAYMENTS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "nowpayments-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OCCUPANCY-PLAN-SQLI-CWE-89",
      "plugin_slug": "occupancy-plan",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-OCCUPANCY-PLAN-SQLI-CWE-89",
      "plugin_slug": "occupancy-plan",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-OCEAN-EXTRA-XSS-CVE-2025-49250",
      "plugin_slug": "ocean-extra",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49250",
      "affected_versions": [
        "2.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49250",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-OMNIPRESS-XSS-CVE-2025-68857",
      "plugin_slug": "omnipress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68857",
      "affected_versions": [
        "1.6.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68857",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONE-CLICK-MIGRATION-XSS-CWE-79",
      "plugin_slug": "one-click-migration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-ONET-REGENERATE-THUMBNAILS-SQLI-CWE-89",
      "plugin_slug": "onet-regenerate-thumbnails",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONET-REGENERATE-THUMBNAILS-SQLI-CWE-89",
      "plugin_slug": "onet-regenerate-thumbnails",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONEX-CUSTOM-POPUP-BUILDER-SSRF-CWE-918",
      "plugin_slug": "onex-custom-popup-builder",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ONEX-CUSTOM-POPUP-BUILDER-SSRF-CWE-918",
      "plugin_slug": "onex-custom-popup-builder",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ONGKOSKIRIM-ID-XSS-CVE-2025-58660",
      "plugin_slug": "ongkoskirim-id",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58660",
      "affected_versions": [
        "1.0.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58660",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONIONBUZZ-VIRAL-QUIZ-SQLI-CVE-2025-53288",
      "plugin_slug": "onionbuzz-viral-quiz",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-53288",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53288",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONIONBUZZ-VIRAL-QUIZ-SQLI-CVE-2025-53288",
      "plugin_slug": "onionbuzz-viral-quiz",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-53288",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53288",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONIONBUZZ-VIRAL-QUIZ-XSS-CVE-2025-53288",
      "plugin_slug": "onionbuzz-viral-quiz",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53288",
      "affected_versions": [
        "1.0.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 38,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53288",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONLYOFFICE-LFI-CVE-2024-53818",
      "plugin_slug": "onlyoffice",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "critical",
      "cve": "CVE-2024-53818",
      "affected_versions": [
        "2.3.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONLYOFFICE-XSS-CVE-2024-53818",
      "plugin_slug": "onlyoffice",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-53818",
      "affected_versions": [
        "2.3.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ONLYOFFICE-XSS-CVE-2024-53818",
      "plugin_slug": "onlyoffice",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-53818",
      "affected_versions": [
        "2.3.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53818",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-OPEN-ACCESS-SSO-XSS-CWE-79",
      "plugin_slug": "open-access-sso",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-OPENAI-TOOLS-FOR-WP-WC-SSRF-CWE-918",
      "plugin_slug": "openai-tools-for-wp-wc",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OPENAI-TOOLS-FOR-WP-WC-SSRF-CWE-918",
      "plugin_slug": "openai-tools-for-wp-wc",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OPTIMOLE-WP-XSS-CVE-2025-15611",
      "plugin_slug": "optimole-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-15611",
      "affected_versions": [
        "4.2.10",
        "4.2.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15611",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OPTISTATE-XSS-CWE-79",
      "plugin_slug": "optistate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-ORDER-CALENDAR-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "order-calendar-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-ORDER-DELIVERY-DATE-FOR-WOOCOMMERCE-KNOWN-CVE-CVE-2025-2942",
      "plugin_slug": "order-delivery-date-for-woocommerce",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-2942",
      "affected_versions": [
        "4.5.3",
        "4.6.0",
        "4.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2942",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ORDER-DELIVERY-DATE-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "order-delivery-date-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ORDER-DELIVERY-DATE-FOR-WOOCOMMERCE-XSS-CVE-2025-2929",
      "plugin_slug": "order-delivery-date-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-2929",
      "affected_versions": [
        "4.5.3",
        "4.6.0",
        "4.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2929",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ORDER-EXPORT-FOR-WOOCOMMERCE-KNOWN-CVE-CVE-2024-43259",
      "plugin_slug": "order-export-for-woocommerce",
      "vuln_class": "known-cve",
      "cwe": "CWE-201",
      "severity": "medium",
      "cve": "CVE-2024-43259",
      "affected_versions": [
        "1.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-43259",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ORDER-EXPORTER-BY-APUSNEST-XSS-CWE-79",
      "plugin_slug": "order-exporter-by-apusnest",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OXYGEN-MYDATA-SSRF-CWE-918",
      "plugin_slug": "oxygen-mydata",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.0.40"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-OXYGEN-MYDATA-SSRF-CWE-918",
      "plugin_slug": "oxygen-mydata",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.0.40"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PACK-ORDERS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "pack-orders-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-PAGBANK-CONNECT-XSS-CWE-79",
      "plugin_slug": "pagbank-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.56.0",
        "4.56.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PAGE-BUILDER-ADD-SSRF-CVE-2026-24626",
      "plugin_slug": "page-builder-add",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-24626",
      "affected_versions": [
        "1.5.3.6",
        "1.5.3.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-24626",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-BUILDER-ADD-SSRF-CVE-2026-24626",
      "plugin_slug": "page-builder-add",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-24626",
      "affected_versions": [
        "1.5.3.6",
        "1.5.3.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-24626",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-BUILDER-ADD-XSS-CVE-2026-24626",
      "plugin_slug": "page-builder-add",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-24626",
      "affected_versions": [
        "1.5.3.6",
        "1.5.3.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 33,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-24626",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-EXPIRE-POPUP-SQLI-CWE-89",
      "plugin_slug": "page-expire-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-EXPIRE-POPUP-SQLI-CWE-89",
      "plugin_slug": "page-expire-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-EXPIRE-POPUP-XSS-CWE-79",
      "plugin_slug": "page-expire-popup",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGE-MANAGER-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "page-manager-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAGELAYER-XSS-CVE-2025-24755",
      "plugin_slug": "pagelayer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24755",
      "affected_versions": [
        "2.1.4",
        "2.1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 42,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24755",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PAGOPAR-WOOCOMMERCE-GATEWAY-XSS-CWE-79",
      "plugin_slug": "pagopar-woocommerce-gateway",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAID-DOWNLOADS-SQLI-CWE-89",
      "plugin_slug": "paid-downloads",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAID-DOWNLOADS-SQLI-CWE-89",
      "plugin_slug": "paid-downloads",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAID-DOWNLOADS-XSS-CWE-79",
      "plugin_slug": "paid-downloads",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAID-MEMBERSHIP-SSRF-CWE-918",
      "plugin_slug": "paid-membership",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.2.6",
        "3.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAID-MEMBERSHIP-SSRF-CWE-918",
      "plugin_slug": "paid-membership",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.2.6",
        "3.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PANORAMA-RCE-CVE-2026-10749",
      "plugin_slug": "panorama",
      "vuln_class": "rce",
      "cwe": "CWE-78",
      "severity": "high",
      "cve": "CVE-2026-10749",
      "affected_versions": [
        "1.7.3",
        "1.7.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-10749",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PARLY-SIMPLE-MULTI-LANGUAGE-XSS-CWE-79",
      "plugin_slug": "parly-simple-multi-language",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2",
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-PARTNERS-XSS-CVE-2024-56291",
      "plugin_slug": "partners",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56291",
      "affected_versions": [
        "0.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56291",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PASSWORD-PROTECTED-XSS-CVE-2025-39531",
      "plugin_slug": "password-protected",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39531",
      "affected_versions": [
        "2.8.2",
        "2.8.3",
        "2.8.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 40,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39531",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PASSWORDS-MANAGER-SQLI-CVE-2024-12613",
      "plugin_slug": "passwords-manager",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-12613",
      "affected_versions": [
        "0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12613",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PASSWORDS-MANAGER-SQLI-CVE-2024-12613",
      "plugin_slug": "passwords-manager",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2024-12613",
      "affected_versions": [
        "0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12613",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PATREON-CONNECT-XSS-CVE-2025-24552",
      "plugin_slug": "patreon-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24552",
      "affected_versions": [
        "1.9.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24552",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PAY-WHAT-YOU-WANT-XSS-CWE-79",
      "plugin_slug": "pay-what-you-want",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.7",
        "1.0.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAY-WITH-CONTACT-FORM-7-SQLI-CVE-2025-49953",
      "plugin_slug": "pay-with-contact-form-7",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-49953",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49953",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAY-WITH-CONTACT-FORM-7-SQLI-CVE-2025-49953",
      "plugin_slug": "pay-with-contact-form-7",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-49953",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49953",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAY-WITH-CONTACT-FORM-7-XSS-CVE-2025-49953",
      "plugin_slug": "pay-with-contact-form-7",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49953",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49953",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAYMENT-ADDONS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "payment-addons-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.16.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-PAYMENT-FORM-FOR-PAYPAL-PRO-SQLI-CWE-89",
      "plugin_slug": "payment-form-for-paypal-pro",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1.73"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAYMENT-FORM-FOR-PAYPAL-PRO-SQLI-CWE-89",
      "plugin_slug": "payment-form-for-paypal-pro",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.73"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PAYMENT-PAGE-XSS-CWE-79",
      "plugin_slug": "payment-page",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PAYTIKO-XSS-CVE-2025-53568",
      "plugin_slug": "paytiko",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53568",
      "affected_versions": [
        "1.4.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53568",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PDF-FOR-GRAVITY-FORMS-SQLI-CWE-89",
      "plugin_slug": "pdf-for-gravity-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "7.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PDF-FOR-GRAVITY-FORMS-SQLI-CWE-89",
      "plugin_slug": "pdf-for-gravity-forms",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "7.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PEACHPAY-FOR-WOOCOMMERCE-XSS-CVE-2024-11361",
      "plugin_slug": "peachpay-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11361",
      "affected_versions": [
        "1.120.53",
        "1.120.54",
        "1.120.55",
        "1.120.56"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11361",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PEPRO-BACS-RECEIPT-UPLOAD-FOR-WOOCOMMERCE-XSS-CVE-2024-54312",
      "plugin_slug": "pepro-bacs-receipt-upload-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54312",
      "affected_versions": [
        "2.8.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54312",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PEPRODEV-UPS-XSS-CWE-79",
      "plugin_slug": "peprodev-ups",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 66,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PETS-XSS-CWE-79",
      "plugin_slug": "pets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PEXLECHRIS-ADMINER-XSS-CWE-79",
      "plugin_slug": "pexlechris-adminer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PHOENIX-MEDIA-RENAME-XSS-CWE-79",
      "plugin_slug": "phoenix-media-rename",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.13.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PHOTO-EXPRESS-FOR-GOOGLE-XSS-CVE-2025-32311",
      "plugin_slug": "photo-express-for-google",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32311",
      "affected_versions": [
        "0.3.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32311",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-CSRF-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-CSRF-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-KNOWN-CVE-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-SQLI-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-SSRF-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-SSRF-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-XSS-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PHOTO-GALLERY-XSS-CVE-2025-32623",
      "plugin_slug": "photo-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-32623",
      "affected_versions": [
        "1.8.42"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PICTURE-GALLERY-SSRF-CVE-2025-22759",
      "plugin_slug": "picture-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-22759",
      "affected_versions": [
        "1.6.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22759",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PICTURE-GALLERY-SSRF-CVE-2025-22759",
      "plugin_slug": "picture-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-22759",
      "affected_versions": [
        "1.6.6"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22759",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PIE-REGISTER-XSS-CVE-2025-69313",
      "plugin_slug": "pie-register",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69313",
      "affected_versions": [
        "3.8.4.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69313",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PITCHPRINT-XSS-CWE-79",
      "plugin_slug": "pitchprint",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLANADAY-API-XSS-CWE-79",
      "plugin_slug": "planaday-api",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 39,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLANYO-ONLINE-RESERVATION-SYSTEM-XSS-CWE-79",
      "plugin_slug": "planyo-online-reservation-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLAYER-LEADERBOARD-SQLI-CWE-89",
      "plugin_slug": "player-leaderboard",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLAYER-LEADERBOARD-SQLI-CWE-89",
      "plugin_slug": "player-leaderboard",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLOVER-KIT-XSS-CWE-79",
      "plugin_slug": "plover-kit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PLUGINS-GARBAGE-COLLECTOR-XSS-CWE-79",
      "plugin_slug": "plugins-garbage-collector",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PLUGINS-ON-STEROIDS-SSRF-CWE-918",
      "plugin_slug": "plugins-on-steroids",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PLUGINS-ON-STEROIDS-SSRF-CWE-918",
      "plugin_slug": "plugins-on-steroids",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PNG-TO-JPG-XSS-CWE-79",
      "plugin_slug": "png-to-jpg",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PODIGEE-XSS-CVE-2026-28114",
      "plugin_slug": "podigee",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-28114",
      "affected_versions": [
        "1.4.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-28114",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PODLOVE-PODCASTING-PLUGIN-FOR-WORDPRESS-XSS-CVE-2025-10412",
      "plugin_slug": "podlove-podcasting-plugin-for-wordpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-10412",
      "affected_versions": [
        "4.5.2",
        "4.5.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 68,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10412",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POKY-PRODUCT-IMPORTER-XSS-CWE-79",
      "plugin_slug": "poky-product-importer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POLL-BUILDER-SQLI-CWE-89",
      "plugin_slug": "poll-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.3.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POLL-BUILDER-SQLI-CWE-89",
      "plugin_slug": "poll-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.3.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POLSKI-XSS-CWE-79",
      "plugin_slug": "polski",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.24.10",
        "1.24.11",
        "1.24.8",
        "1.24.9",
        "1.25.0",
        "1.25.1",
        "1.25.2",
        "1.25.3",
        "1.25.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 45,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POLYLANG-SQLI-CWE-89",
      "plugin_slug": "polylang",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.8.5",
        "3.8.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POLYLANG-SQLI-CWE-89",
      "plugin_slug": "polylang",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.8.5",
        "3.8.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PONDOL-BBS-SQLI-CVE-2025-11926",
      "plugin_slug": "pondol-bbs",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-11926",
      "affected_versions": [
        "1.1.8.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11926",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PONDOL-BBS-SQLI-CVE-2025-11926",
      "plugin_slug": "pondol-bbs",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-11926",
      "affected_versions": [
        "1.1.8.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11926",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PONDOL-BBS-XSS-CVE-2025-11926",
      "plugin_slug": "pondol-bbs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11926",
      "affected_versions": [
        "1.1.8.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11926",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POP-UP-POP-UP-XSS-CWE-79",
      "plugin_slug": "pop-up-pop-up",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POPULARIS-EXTRA-XSS-CVE-2026-1165",
      "plugin_slug": "popularis-extra",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1165",
      "affected_versions": [
        "1.2.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1165",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POPUP-BOX-SQLI-CVE-2021-24460",
      "plugin_slug": "popup-box",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2021-24460",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24460",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-SSRF-CVE-2025-15611",
      "plugin_slug": "popup-box",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-15611",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15611",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CWE-79",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-27414",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2023-27414",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-27414",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-4390",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-4390",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-4390",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-5343",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-5343",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-5343",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-5809",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-5809",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-5809",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-5874",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-5874",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-5874",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2023-6591",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-6591",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-6591",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BOX-XSS-CVE-2024-9599",
      "plugin_slug": "popup-box",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-9599",
      "affected_versions": [
        "3.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9599",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POPUP-BUILDER-SQLI-CVE-2024-10517",
      "plugin_slug": "popup-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-10517",
      "affected_versions": [
        "4.4.4",
        "4.4.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10517",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POPUP-BUILDER-SQLI-CVE-2024-10517",
      "plugin_slug": "popup-builder",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-10517",
      "affected_versions": [
        "4.4.4",
        "4.4.5"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10517",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-AND-PAGE-BUILDER-XSS-CVE-2024-13529",
      "plugin_slug": "post-and-page-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13529",
      "affected_versions": [
        "1.27.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13529",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-COMMENT-NOTIFICATION-TO-MULTIPLE-USER-XSS-CWE-79",
      "plugin_slug": "post-comment-notification-to-multiple-user",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POST-GRID-DESERIALIZATION-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-KNOWN-CVE-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-KNOWN-CVE-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-LFI-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-SQLI-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-XSS-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-GRID-XSS-CVE-2025-31048",
      "plugin_slug": "post-grid",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-31048",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 5,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31048",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-IDEAS-SQLI-CVE-2024-10400",
      "plugin_slug": "post-ideas",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-10400",
      "affected_versions": [
        "2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10400",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-IDEAS-SQLI-CVE-2024-10400",
      "plugin_slug": "post-ideas",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-10400",
      "affected_versions": [
        "2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10400",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-IDEAS-XSS-CVE-2024-10400",
      "plugin_slug": "post-ideas",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-10400",
      "affected_versions": [
        "2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10400",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-SLIDER-AND-CAROUSEL-XSS-CVE-2025-1485",
      "plugin_slug": "post-slider-and-carousel",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1485",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1485",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POST-SMTP-XSS-CVE-2025-53213",
      "plugin_slug": "post-smtp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53213",
      "affected_versions": [
        "3.9.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53213",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POST-SNIPPETS-CSRF-CVE-2026-56058",
      "plugin_slug": "post-snippets",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "critical",
      "cve": "CVE-2026-56058",
      "affected_versions": [
        "2.5.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56058",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-SNIPPETS-XSS-CWE-79",
      "plugin_slug": "post-snippets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2.0",
        "4.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POST-SNIPPETS-XSS-CVE-2026-56058",
      "plugin_slug": "post-snippets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-56058",
      "affected_versions": [
        "2.5.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56058",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-POST-TO-GOOGLE-MY-BUSINESS-XSS-CWE-79",
      "plugin_slug": "post-to-google-my-business",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POSTEN-BRING-CHECKOUT-XSS-CWE-79",
      "plugin_slug": "posten-bring-checkout",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.57",
        "1.1.58",
        "1.1.59",
        "1.1.60"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-POSTEX-ADVANCED-SHIPPING-METHOD-SSRF-CWE-918",
      "plugin_slug": "postex-advanced-shipping-method",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.1",
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-POSTEX-ADVANCED-SHIPPING-METHOD-SSRF-CWE-918",
      "plugin_slug": "postex-advanced-shipping-method",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.1",
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-POSTI-SHIPPING-XSS-CVE-2024-11083",
      "plugin_slug": "posti-shipping",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11083",
      "affected_versions": [
        "3.10.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11083",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-POSTS-SOCIAL-SHARES-COUNT-XSS-CWE-79",
      "plugin_slug": "posts-social-shares-count",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-POWERPRESS-SSRF-CVE-2025-13680",
      "plugin_slug": "powerpress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-13680",
      "affected_versions": [
        "11.16.10",
        "11.16.11",
        "11.16.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13680",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POWERPRESS-SSRF-CVE-2025-13680",
      "plugin_slug": "powerpress",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-13680",
      "affected_versions": [
        "11.16.10",
        "11.16.11",
        "11.16.9"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13680",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POWERPRESS-XSS-CVE-2025-13680",
      "plugin_slug": "powerpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-13680",
      "affected_versions": [
        "11.16.10",
        "11.16.11",
        "11.16.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 141,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13680",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-POWERSTRIP-KNOWN-CVE-CVE-2008-5725",
      "plugin_slug": "powerstrip",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "medium",
      "cve": "CVE-2008-5725",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2008-5725",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-RCE-CWE-94",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-RCE-CWE-95",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-SQLI-CWE-89",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-SQLI-CWE-89",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-SSRF-CWE-918",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-SSRF-CWE-918",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PPV-LIVE-WEBCAMS-XSS-CWE-79",
      "plugin_slug": "ppv-live-webcams",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-XSS-CVE-2026-1319",
      "plugin_slug": "premmerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1319",
      "affected_versions": [
        "1.3.23"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1319",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-REDIRECT-MANAGER-XSS-CVE-2026-25455",
      "plugin_slug": "premmerce-redirect-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25455",
      "affected_versions": [
        "1.0.14"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25455",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-SEARCH-XSS-CWE-79",
      "plugin_slug": "premmerce-search",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-USER-ROLES-XSS-CVE-2025-60192",
      "plugin_slug": "premmerce-user-roles",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-60192",
      "affected_versions": [
        "1.0.15"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60192",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-WOOCOMMERCE-BRANDS-XSS-CWE-79",
      "plugin_slug": "premmerce-woocommerce-brands",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-WOOCOMMERCE-WHOLESALE-PRICING-XSS-CVE-2025-46243",
      "plugin_slug": "premmerce-woocommerce-wholesale-pricing",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-46243",
      "affected_versions": [
        "1.1.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-46243",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PREMMERCE-WOOCOMMERCE-WISHLIST-XSS-CVE-2025-54052",
      "plugin_slug": "premmerce-woocommerce-wishlist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-54052",
      "affected_versions": [
        "1.1.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54052",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRESSGO-BUILDER-XSS-CWE-79",
      "plugin_slug": "pressgo-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.5.1",
        "2.5.10",
        "2.5.2",
        "2.5.3",
        "2.5.4",
        "2.5.5",
        "2.5.6",
        "2.5.7",
        "2.5.8",
        "2.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 39,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PRESSROOM-SSRF-CVE-2025-39487",
      "plugin_slug": "pressroom",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-39487",
      "affected_versions": [
        "1.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39487",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRESSROOM-SSRF-CVE-2025-39487",
      "plugin_slug": "pressroom",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-39487",
      "affected_versions": [
        "1.3.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39487",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRESSROOM-XSS-CVE-2025-39487",
      "plugin_slug": "pressroom",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39487",
      "affected_versions": [
        "1.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 33,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39487",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRETTY-SIMPLE-POPUP-BUILDER-XSS-CWE-79",
      "plugin_slug": "pretty-simple-popup-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRETTYPHOTO-XSS-CVE-2025-58612",
      "plugin_slug": "prettyphoto",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-58612",
      "affected_versions": [
        "1.2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58612",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRIMARY-ADDON-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "primary-addon-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PRIMER-MYDATA-XSS-CWE-79",
      "plugin_slug": "primer-mydata",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PRINT-INVOICES-PACKING-SLIP-LABELS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "print-invoices-packing-slip-labels-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.9.7",
        "4.9.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRINT-MY-BLOG-XSS-CWE-79",
      "plugin_slug": "print-my-blog",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.27.17"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRIVACY-CONSENT-ASSISTANT-SQLI-CWE-89",
      "plugin_slug": "privacy-consent-assistant",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PRIVACY-CONSENT-ASSISTANT-SQLI-CWE-89",
      "plugin_slug": "privacy-consent-assistant",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PRODUCT-ADDONS-CSRF-CVE-2026-57343",
      "plugin_slug": "product-addons",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-57343",
      "affected_versions": [
        "1.6.16"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57343",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PRODUCT-ADDONS-CSRF-CVE-2026-57424",
      "plugin_slug": "product-addons",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2026-57424",
      "affected_versions": [
        "1.6.17",
        "1.6.18"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57424",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PRODUCT-ADDONS-DESERIALIZATION-CVE-2026-57343",
      "plugin_slug": "product-addons",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-57343",
      "affected_versions": [
        "1.6.16"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57343",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PRODUCT-ADDONS-DESERIALIZATION-CVE-2026-57424",
      "plugin_slug": "product-addons",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-57424",
      "affected_versions": [
        "1.6.17",
        "1.6.18"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57424",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PRODUCT-DESIGNER-CSRF-CVE-2024-11385",
      "plugin_slug": "product-designer",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2024-11385",
      "affected_versions": [
        "1.0.40"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11385",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRODUCT-DESIGNER-DESERIALIZATION-CVE-2024-11385",
      "plugin_slug": "product-designer",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "critical",
      "cve": "CVE-2024-11385",
      "affected_versions": [
        "1.0.40"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11385",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRODUCT-DESIGNER-LFI-CVE-2024-11385",
      "plugin_slug": "product-designer",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "high",
      "cve": "CVE-2024-11385",
      "affected_versions": [
        "1.0.40"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11385",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRODUCT-QUOTE-CART-FOR-WC-XSS-CWE-79",
      "plugin_slug": "product-quote-cart-for-wc",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-19"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-BROKEN-ACCESS-CONTROL-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "high",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-BROKEN-ACCESS-CONTROL-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "critical",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-CSRF-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-CSRF-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-FILE-UPLOAD-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-KNOWN-CVE-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-KNOWN-CVE-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "critical",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-KNOWN-CVE-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-620",
      "severity": "critical",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-KNOWN-CVE-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-XSS-CVE-2025-11267",
      "plugin_slug": "profile-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11267",
      "affected_versions": [
        "3.16.3",
        "3.16.4",
        "3.16.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 60,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11267",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-XSS-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILE-BUILDER-XSS-CVE-2025-69101",
      "plugin_slug": "profile-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-69101",
      "affected_versions": [
        "3.4.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69101",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-PROFILEGRID-USER-PROFILES-GROUPS-AND-COMMUNITIES-SSRF-CVE-2026-57617",
      "plugin_slug": "profilegrid-user-profiles-groups-and-communities",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-57617",
      "affected_versions": [
        "5.9.9.8",
        "5.9.9.9",
        "6.0.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57617",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PROFILEGRID-USER-PROFILES-GROUPS-AND-COMMUNITIES-SSRF-CVE-2026-57617",
      "plugin_slug": "profilegrid-user-profiles-groups-and-communities",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-57617",
      "affected_versions": [
        "5.9.9.8",
        "5.9.9.9",
        "6.0.0.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-57617",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PROJECT-COST-CALCULATOR-XSS-CVE-2025-48108",
      "plugin_slug": "project-cost-calculator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48108",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48108",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PROJECTOPIA-CORE-SSRF-CVE-2025-67565",
      "plugin_slug": "projectopia-core",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-67565",
      "affected_versions": [
        "5.1.25.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67565",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PROJECTOPIA-CORE-SSRF-CVE-2025-67565",
      "plugin_slug": "projectopia-core",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-67565",
      "affected_versions": [
        "5.1.25.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67565",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PROJECTOPIA-CORE-XSS-CVE-2025-67565",
      "plugin_slug": "projectopia-core",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67565",
      "affected_versions": [
        "5.1.25.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 40,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67565",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PROMISSA-XSS-CWE-79",
      "plugin_slug": "promissa",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-PRORANK-SEO-SSRF-CWE-918",
      "plugin_slug": "prorank-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.4.1",
        "1.4.2",
        "1.4.3",
        "1.4.4",
        "1.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PRORANK-SEO-SSRF-CWE-918",
      "plugin_slug": "prorank-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.4.1",
        "1.4.2",
        "1.4.3",
        "1.4.4",
        "1.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PROSOLUTION-WP-CLIENT-SQLI-CWE-89",
      "plugin_slug": "prosolution-wp-client",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PROSOLUTION-WP-CLIENT-SQLI-CWE-89",
      "plugin_slug": "prosolution-wp-client",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 96,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PROSOLUTION-WP-CLIENT-SSRF-CWE-918",
      "plugin_slug": "prosolution-wp-client",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PROSOLUTION-WP-CLIENT-SSRF-CWE-918",
      "plugin_slug": "prosolution-wp-client",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PROSOLUTION-WP-CLIENT-XSS-CWE-79",
      "plugin_slug": "prosolution-wp-client",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 311,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PUFFERGO-XSS-CWE-79",
      "plugin_slug": "puffergo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.11.3",
        "0.12.0",
        "0.13.0",
        "0.13.1",
        "0.13.3",
        "0.14.0",
        "0.15.0",
        "0.16.0",
        "0.17.0",
        "0.18.0",
        "0.18.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 91,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PURGE-VARNISH-XSS-CVE-2025-58861",
      "plugin_slug": "purge-varnish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58861",
      "affected_versions": [
        "1.1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58861",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PUSH-NOTIFICATION-FOR-POST-AND-BUDDYPRESS-RCE-CWE-94",
      "plugin_slug": "push-notification-for-post-and-buddypress",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "3.16",
        "3.17",
        "3.18",
        "3.20"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PUSH-NOTIFICATION-FOR-POST-AND-BUDDYPRESS-RCE-CWE-95",
      "plugin_slug": "push-notification-for-post-and-buddypress",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "3.16",
        "3.17",
        "3.18",
        "3.20"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PUSHENGAGE-SSRF-CVE-2026-4058",
      "plugin_slug": "pushengage",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-4058",
      "affected_versions": [
        "4.2.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4058",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PUSHENGAGE-SSRF-CVE-2026-4058",
      "plugin_slug": "pushengage",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-4058",
      "affected_versions": [
        "4.2.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4058",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-PVERIFY-SQLI-CWE-89",
      "plugin_slug": "pverify",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PVERIFY-SQLI-CWE-89",
      "plugin_slug": "pverify",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PW-BULK-EDIT-XSS-CVE-2025-47628",
      "plugin_slug": "pw-bulk-edit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47628",
      "affected_versions": [
        "2.141"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47628",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PWA-XSS-CVE-2024-8967",
      "plugin_slug": "pwa",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-8967",
      "affected_versions": [
        "0.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8967",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-PWA-FOR-WP-SSRF-CWE-918",
      "plugin_slug": "pwa-for-wp",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.7.86",
        "1.7.87"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-PWA-FOR-WP-SSRF-CWE-918",
      "plugin_slug": "pwa-for-wp",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.7.86",
        "1.7.87"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-QA-HEATMAP-ANALYTICS-XSS-CWE-79",
      "plugin_slug": "qa-heatmap-analytics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.2.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-QUBOTCHAT-SQLI-CWE-89",
      "plugin_slug": "qubotchat",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-QUBOTCHAT-SQLI-CWE-89",
      "plugin_slug": "qubotchat",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-QUBOTCHAT-SSRF-CWE-918",
      "plugin_slug": "qubotchat",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-QUBOTCHAT-SSRF-CWE-918",
      "plugin_slug": "qubotchat",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-QUBOTCHAT-XSS-CWE-79",
      "plugin_slug": "qubotchat",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-QUICK-PAYPAL-PAYMENTS-XSS-CWE-79",
      "plugin_slug": "quick-paypal-payments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.7.50"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-QUICK-PLAYGROUND-XSS-CWE-79",
      "plugin_slug": "quick-playground",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-QUICK-VARIABLE-PRODUCTS-XSS-CWE-79",
      "plugin_slug": "quick-variable-products",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-QUILLFORMS-RCE-CWE-94",
      "plugin_slug": "quillforms",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "5.6.1",
        "5.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-QUILLFORMS-RCE-CWE-95",
      "plugin_slug": "quillforms",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "5.6.1",
        "5.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-QUOTE-MASTER-XSS-CWE-79",
      "plugin_slug": "quote-master",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-QYRR-CODE-XSS-CVE-2025-62911",
      "plugin_slug": "qyrr-code",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62911",
      "affected_versions": [
        "2.0.11",
        "2.0.12"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62911",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RADIO-STATION-XSS-CWE-79",
      "plugin_slug": "radio-station",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.7.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RAFFLEPRESS-XSS-CVE-2025-52802",
      "plugin_slug": "rafflepress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-52802",
      "affected_versions": [
        "1.12.23",
        "1.12.24"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-52802",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-RANKOLOGY-SEO-AND-ANALYTICS-TOOL-XSS-CWE-79",
      "plugin_slug": "rankology-seo-and-analytics-tool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-RAVPAGE-DESERIALIZATION-CVE-2025-27270",
      "plugin_slug": "ravpage",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "critical",
      "cve": "CVE-2025-27270",
      "affected_versions": [
        "2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27270",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-RAVPAGE-XSS-CVE-2025-27270",
      "plugin_slug": "ravpage",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-27270",
      "affected_versions": [
        "2.5"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27270",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-READ-MORE-WITHOUT-REFRESH-XSS-CWE-79",
      "plugin_slug": "read-more-without-refresh",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-READERS-FROM-RSS-2-BLOG-XSS-CWE-79",
      "plugin_slug": "readers-from-rss-2-blog",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.1.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-REAL-ESTATE-MANAGER-XSS-CVE-2024-13829",
      "plugin_slug": "real-estate-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13829",
      "affected_versions": [
        "7.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13829",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REAL3D-FLIPBOOK-LITE-XSS-CWE-79",
      "plugin_slug": "real3d-flipbook-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.0",
        "5.0.1",
        "5.0.2",
        "5.0.3",
        "5.0.4",
        "5.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 85,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-REALA11Y-XSS-CWE-79",
      "plugin_slug": "reala11y",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-26"
    },
    {
      "id": "CLR-WP-REDI-RESTAURANT-RESERVATION-XSS-CVE-2025-47613",
      "plugin_slug": "redi-restaurant-reservation",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47613",
      "affected_versions": [
        "26.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47613",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RELATED-POSTS-THUMBNAILS-XSS-CWE-79",
      "plugin_slug": "related-posts-thumbnails",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-RELEVANSSI-XSS-CVE-2025-5209",
      "plugin_slug": "relevanssi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-5209",
      "affected_versions": [
        "4.27.1",
        "4.27.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-5209",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RELINKA-XSS-CWE-79",
      "plugin_slug": "relinka",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0",
        "1.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 39,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-RENCONTRE-SQLI-CWE-89",
      "plugin_slug": "rencontre",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.13.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RENCONTRE-SQLI-CWE-89",
      "plugin_slug": "rencontre",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.13.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RENCONTRE-XSS-CWE-79",
      "plugin_slug": "rencontre",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.13.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RESPONSIVE-ADD-ONS-XSS-CVE-2024-13692",
      "plugin_slug": "responsive-add-ons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13692",
      "affected_versions": [
        "3.5.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13692",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RESPONSIVE-ADDONS-FOR-ELEMENTOR-KNOWN-CVE-CVE-2025-39578",
      "plugin_slug": "responsive-addons-for-elementor",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2025-39578",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39578",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-RESPONSIVE-ADDONS-FOR-ELEMENTOR-LFI-CVE-2025-39578",
      "plugin_slug": "responsive-addons-for-elementor",
      "vuln_class": "lfi",
      "cwe": "CWE-98",
      "severity": "high",
      "cve": "CVE-2025-39578",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39578",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-RESPONSIVE-ADDONS-FOR-ELEMENTOR-XSS-CVE-2025-39578",
      "plugin_slug": "responsive-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-39578",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39578",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-RESPONSIVE-LIGHTBOX-XSS-CVE-2026-8172",
      "plugin_slug": "responsive-lightbox",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-8172",
      "affected_versions": [
        "2.7.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-8172",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REST-ROUTES-XSS-CWE-79",
      "plugin_slug": "rest-routes",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-RESTAURANT-CAFE-ADDON-FOR-ELEMENTOR-XSS-CVE-2024-10798",
      "plugin_slug": "restaurant-cafe-addon-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-10798",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10798",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-RESTFUL-SYNDICATION-XSS-CVE-2025-6574",
      "plugin_slug": "restful-syndication",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-6574",
      "affected_versions": [
        "1.7.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6574",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RESTRICT-CONTENT-XSS-CWE-79",
      "plugin_slug": "restrict-content",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 60,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RESTRICT-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "restrict-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-RESTRICTED-CONTENT-XSS-CWE-79",
      "plugin_slug": "restricted-content",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.5",
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REVECHAT-XSS-CWE-79",
      "plugin_slug": "revechat",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.4.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REVIEW-SCHEMA-XSS-CWE-79",
      "plugin_slug": "review-schema",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-REVIEW-STARS-COUNT-FOR-WOOCOMMERCE-SQLI-CWE-89",
      "plugin_slug": "review-stars-count-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REVIEW-STARS-COUNT-FOR-WOOCOMMERCE-SQLI-CWE-89",
      "plugin_slug": "review-stars-count-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REVIEW-STARS-COUNT-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "review-stars-count-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REVIEWFIC-XSS-CWE-79",
      "plugin_slug": "reviewfic",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.47"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 17,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-REZGO-SSRF-CWE-918",
      "plugin_slug": "rezgo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.24",
        "4.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REZGO-SSRF-CWE-918",
      "plugin_slug": "rezgo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.24",
        "4.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 43,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-REZGO-XSS-CWE-79",
      "plugin_slug": "rezgo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.24",
        "4.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 396,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RICHTEXTEDITOR-XSS-CVE-2025-31566",
      "plugin_slug": "richtexteditor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-31566",
      "affected_versions": [
        "1.0.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-31566",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RIS-VERSION-SWITCHER-SSRF-CVE-2025-57970",
      "plugin_slug": "ris-version-switcher",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-57970",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57970",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RIS-VERSION-SWITCHER-SSRF-CVE-2025-57970",
      "plugin_slug": "ris-version-switcher",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-57970",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-57970",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ROCKETSHIP-SEO-SSRF-CWE-918",
      "plugin_slug": "rocketship-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.66",
        "1.0.67"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ROCKETSHIP-SEO-SSRF-CWE-918",
      "plugin_slug": "rocketship-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.66",
        "1.0.67"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ROSES-LIKE-THIS-XSS-CWE-79",
      "plugin_slug": "roses-like-this",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ROYAL-ELEMENTOR-ADDONS-SSRF-CVE-2026-3017",
      "plugin_slug": "royal-elementor-addons",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-3017",
      "affected_versions": [
        "1.7.1064"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3017",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ROYAL-ELEMENTOR-ADDONS-SSRF-CVE-2026-3017",
      "plugin_slug": "royal-elementor-addons",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-3017",
      "affected_versions": [
        "1.7.1064"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3017",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ROYAL-ELEMENTOR-ADDONS-XSS-CVE-2026-3017",
      "plugin_slug": "royal-elementor-addons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-3017",
      "affected_versions": [
        "1.7.1064"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 35,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3017",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-RSS-CHIMP-XSS-CWE-79",
      "plugin_slug": "rss-chimp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-S2MEMBER-XSS-CWE-79",
      "plugin_slug": "s2member",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "260508"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SAILTHRU-TRIGGERMAIL-XSS-CVE-2024-12501",
      "plugin_slug": "sailthru-triggermail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12501",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12501",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SAILTHRU-TRIGGERMAIL-XSS-CVE-2024-12501",
      "plugin_slug": "sailthru-triggermail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-12501",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12501",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SALMANPATNEE-MPGS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "salmanpatnee-mpgs-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-SALON-BOOKING-SYSTEM-RCE-CWE-94",
      "plugin_slug": "salon-booking-system",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "10.30.33"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SALON-BOOKING-SYSTEM-RCE-CWE-95",
      "plugin_slug": "salon-booking-system",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "10.30.33"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SALON-BOOKING-SYSTEM-XSS-CWE-79",
      "plugin_slug": "salon-booking-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "10.30.33"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 21,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SAMEDAYCOURIER-SHIPPING-XSS-CWE-79",
      "plugin_slug": "samedaycourier-shipping",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.11.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SAMPLE-DATA-EXPORT-SQLI-CWE-89",
      "plugin_slug": "sample-data-export",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SAMPLE-DATA-EXPORT-SQLI-CWE-89",
      "plugin_slug": "sample-data-export",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SASSY-SOCIAL-SHARE-XSS-CVE-2025-39539",
      "plugin_slug": "sassy-social-share",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-39539",
      "affected_versions": [
        "3.3.79"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39539",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SCAND-MULTI-MAILER-XSS-CVE-2025-32517",
      "plugin_slug": "scand-multi-mailer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32517",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32517",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SCHEMA-CSRF-CVE-2023-36682",
      "plugin_slug": "schema",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2023-36682",
      "affected_versions": [
        "1.7.9.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-36682",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHEMA-KNOWN-CVE-CVE-2024-1564",
      "plugin_slug": "schema",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2024-1564",
      "affected_versions": [
        "1.7.9.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-1564",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHEMA-XSS-CWE-79",
      "plugin_slug": "schema",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.9.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHEMA-XSS-CVE-2022-33154",
      "plugin_slug": "schema",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-33154",
      "affected_versions": [
        "1.7.9.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-33154",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-BROKEN-ACCESS-CONTROL-CVE-2024-12610",
      "plugin_slug": "school-management-system",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2024-12610",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12610",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-BROKEN-ACCESS-CONTROL-CVE-2024-12611",
      "plugin_slug": "school-management-system",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2024-12611",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12611",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-FILE-UPLOAD-CVE-2024-9659",
      "plugin_slug": "school-management-system",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2024-9659",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9659",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-FILE-UPLOAD-CVE-2024-9660",
      "plugin_slug": "school-management-system",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2024-9660",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9660",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-KNOWN-CVE-CVE-2024-9658",
      "plugin_slug": "school-management-system",
      "vuln_class": "known-cve",
      "cwe": "CWE-288",
      "severity": "high",
      "cve": "CVE-2024-9658",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9658",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42566",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42566",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42566",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42567",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42567",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42567",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42568",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42568",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42568",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42569",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42569",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42569",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42570",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42570",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42570",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42571",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42571",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42571",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42572",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42572",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42572",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42573",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42573",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42573",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42574",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42574",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42574",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-42575",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-42575",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-42575",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CWE-89",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-12607",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2024-12607",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12607",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCHOOL-MANAGEMENT-SYSTEM-SQLI-CVE-2024-12609",
      "plugin_slug": "school-management-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2024-12609",
      "affected_versions": [
        "5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12609",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SCROLL-RSS-EXCERPT-XSS-CWE-79",
      "plugin_slug": "scroll-rss-excerpt",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SCROLL-TO-UP-XSS-CVE-2025-39478",
      "plugin_slug": "scroll-to-up",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39478",
      "affected_versions": [
        "2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39478",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SCROLLSEQUENCE-XSS-CWE-79",
      "plugin_slug": "scrollsequence",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SCUDO-SECURITY-XSS-CWE-79",
      "plugin_slug": "scudo-security",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-SEARCH-CLOUD-ONE-XSS-CWE-79",
      "plugin_slug": "search-cloud-one",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SELL-BTC-BY-HAYYATAPPS-XSS-CVE-2025-69368",
      "plugin_slug": "sell-btc-by-hayyatapps",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69368",
      "affected_versions": [
        "2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69368",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-SELLSY-XSS-CWE-79",
      "plugin_slug": "sellsy",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEMA-API-SQLI-CWE-89",
      "plugin_slug": "sema-api",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "6.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEMA-API-SQLI-CWE-89",
      "plugin_slug": "sema-api",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "6.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 30,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEMA-API-XSS-CWE-79",
      "plugin_slug": "sema-api",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEMTOO-XSS-CWE-79",
      "plugin_slug": "semtoo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SEO-HELP-SQLI-CWE-89",
      "plugin_slug": "seo-help",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "6.8.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEO-HELP-SQLI-CWE-89",
      "plugin_slug": "seo-help",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "6.8.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEO-LANDING-PAGE-GENERATOR-SQLI-CWE-89",
      "plugin_slug": "seo-landing-page-generator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.72.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEO-LANDING-PAGE-GENERATOR-SQLI-CWE-89",
      "plugin_slug": "seo-landing-page-generator",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.72.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEO-LANDING-PAGE-GENERATOR-XSS-CWE-79",
      "plugin_slug": "seo-landing-page-generator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.72.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEO-OPTIMIZED-IMAGES-XSS-CWE-79",
      "plugin_slug": "seo-optimized-images",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SEO-SLIDER-XSS-CVE-2025-62759",
      "plugin_slug": "seo-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-62759",
      "affected_versions": [
        "0.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62759",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEUR-SQLI-CVE-2025-39378",
      "plugin_slug": "seur",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-39378",
      "affected_versions": [
        "2.2.29"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39378",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SEUR-SQLI-CVE-2025-39378",
      "plugin_slug": "seur",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-39378",
      "affected_versions": [
        "2.2.29"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39378",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHARE-THIS-IMAGE-XSS-CVE-2026-1843",
      "plugin_slug": "share-this-image",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-1843",
      "affected_versions": [
        "2.16"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-1843",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHAREADRAFT-XSS-CWE-79",
      "plugin_slug": "shareadraft",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6",
        "1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SHIP-DISCOUNTS-XSS-CWE-79",
      "plugin_slug": "ship-discounts",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-SHIP-PER-PRODUCT-XSS-CWE-79",
      "plugin_slug": "ship-per-product",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHIPANY-SSRF-CWE-918",
      "plugin_slug": "shipany",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.1.104",
        "1.1.105"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-SHIPANY-SSRF-CWE-918",
      "plugin_slug": "shipany",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.1.104",
        "1.1.105"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-SHIPTIMIZE-FOR-WOOCOMMERCE-SQLI-CVE-2025-30853",
      "plugin_slug": "shiptimize-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-30853",
      "affected_versions": [
        "3.1.86"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30853",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHIPTIMIZE-FOR-WOOCOMMERCE-SQLI-CVE-2025-30853",
      "plugin_slug": "shiptimize-for-woocommerce",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-30853",
      "affected_versions": [
        "3.1.86"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30853",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHIPTIMIZE-FOR-WOOCOMMERCE-XSS-CVE-2025-30853",
      "plugin_slug": "shiptimize-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-30853",
      "affected_versions": [
        "3.1.86"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30853",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHMAPPER-BY-TEPLITSA-XSS-CVE-2024-56260",
      "plugin_slug": "shmapper-by-teplitsa",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56260",
      "affected_versions": [
        "1.5.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56260",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHOP-INFORMATION-SYSTEM-SQLI-CWE-89",
      "plugin_slug": "shop-information-system",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1.8",
        "1.1.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SHOP-INFORMATION-SYSTEM-XSS-CWE-79",
      "plugin_slug": "shop-information-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.8",
        "1.1.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SHORTCODE-KNOWN-CVE-CVE-2025-60124",
      "plugin_slug": "shortcode",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-60124",
      "affected_versions": [
        "0.8.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60124",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHORTCODE-GALLERY-FOR-MATTERPORT-SHOWCASE-XSS-CWE-79",
      "plugin_slug": "shortcode-gallery-for-matterport-showcase",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SHORTCODES-ULTIMATE-XSS-CVE-2025-1324",
      "plugin_slug": "shortcodes-ultimate",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-1324",
      "affected_versions": [
        "7.8.2",
        "7.8.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-1324",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHORTLINKSPRO-XSS-CVE-2025-5760",
      "plugin_slug": "shortlinkspro",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-5760",
      "affected_versions": [
        "1.2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-5760",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SHOW-PAGES-LIST-XSS-CVE-2025-58677",
      "plugin_slug": "show-pages-list",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58677",
      "affected_versions": [
        "1.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58677",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIFENCY-ADDONS-XSS-CWE-79",
      "plugin_slug": "sifency-addons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SIGN-UP-SHEETS-XSS-CVE-2025-39569",
      "plugin_slug": "sign-up-sheets",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-39569",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39569",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIMPLE-DOWNLOAD-MONITOR-SSRF-CWE-918",
      "plugin_slug": "simple-download-monitor",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "4.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-DOWNLOAD-MONITOR-SSRF-CWE-918",
      "plugin_slug": "simple-download-monitor",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "4.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-EVENT-PLANNER-XSS-CWE-79",
      "plugin_slug": "simple-event-planner",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SIMPLE-FORM-KNOWN-CVE-CVE-2019-16676",
      "plugin_slug": "simple-form",
      "vuln_class": "known-cve",
      "cwe": "CWE-20",
      "severity": "critical",
      "cve": "CVE-2019-16676",
      "affected_versions": [
        "3.9.6",
        "3.9.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-16676",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-SIMPLE-POLL-XSS-CWE-79",
      "plugin_slug": "simple-poll",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIMPLE-POST-META-MANAGER-XSS-CWE-79",
      "plugin_slug": "simple-post-meta-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIMPLE-RETAIL-MENUS-XSS-CWE-79",
      "plugin_slug": "simple-retail-menus",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIMPLE-SEO-CSRF-CVE-2022-36404",
      "plugin_slug": "simple-seo",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2022-36404",
      "affected_versions": [
        "0.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-36404",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-SEO-CSRF-CVE-2022-44627",
      "plugin_slug": "simple-seo",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2022-44627",
      "affected_versions": [
        "0.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-44627",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-SEO-CSRF-CVE-2023-45269",
      "plugin_slug": "simple-seo",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2023-45269",
      "affected_versions": [
        "0.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-45269",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-SEO-XSS-CVE-2022-1628",
      "plugin_slug": "simple-seo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-1628",
      "affected_versions": [
        "0.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-1628",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLE-SOCIAL-BUTTONS-XSS-CWE-79",
      "plugin_slug": "simple-social-buttons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SIMPLE-XML-SITEMAP-XSS-CVE-2025-62128",
      "plugin_slug": "simple-xml-sitemap",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-62128",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62128",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIMPLY-GALLERY-BLOCK-XSS-CWE-79",
      "plugin_slug": "simply-gallery-block",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLYBOOK-FILE-UPLOAD-CVE-2019-11887",
      "plugin_slug": "simplybook",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2019-11887",
      "affected_versions": [
        "3.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11887",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLYBOOK-KNOWN-CVE-CVE-2019-11489",
      "plugin_slug": "simplybook",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2019-11489",
      "affected_versions": [
        "3.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11489",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIMPLYBOOK-KNOWN-CVE-CVE-2019-11488",
      "plugin_slug": "simplybook",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "high",
      "cve": "CVE-2019-11488",
      "affected_versions": [
        "3.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2019-11488",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SIRV-SQLI-CWE-89",
      "plugin_slug": "sirv",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "8.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIRV-SQLI-CWE-89",
      "plugin_slug": "sirv",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "8.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SIRV-XSS-CWE-79",
      "plugin_slug": "sirv",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 30,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SITE-FIRST-SEO-XSS-CWE-79",
      "plugin_slug": "site-first-seo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.6",
        "1.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 45,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-SITE-SEARCH-360-XSS-CVE-2024-13349",
      "plugin_slug": "site-search-360",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13349",
      "affected_versions": [
        "2.1.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13349",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SITESKYLINE-EMAIL-CAMPAIGN-MANAGER-XSS-CWE-79",
      "plugin_slug": "siteskyline-email-campaign-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.1",
        "1.0.2",
        "1.0.3",
        "1.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-SITESUPERCHARGER-SSRF-CWE-918",
      "plugin_slug": "sitesupercharger",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "5.8.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SITESUPERCHARGER-SSRF-CWE-918",
      "plugin_slug": "sitesupercharger",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "5.8.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SKILLBARS-XSS-CVE-2024-11907",
      "plugin_slug": "skillbars",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11907",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11907",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SKT-ADDONS-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "skt-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.9",
        "4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SKT-NURCAPTCHA-XSS-CWE-79",
      "plugin_slug": "skt-nurcaptcha",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.6.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-15"
    },
    {
      "id": "CLR-WP-SKT-TEMPLATES-XSS-CWE-79",
      "plugin_slug": "skt-templates",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.30.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SKYNET-MALAYSIA-SQLI-CWE-89",
      "plugin_slug": "skynet-malaysia",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.0.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-SKYNET-MALAYSIA-SQLI-CWE-89",
      "plugin_slug": "skynet-malaysia",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.0.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-SKYNET-MALAYSIA-XSS-CWE-79",
      "plugin_slug": "skynet-malaysia",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-SLICED-INVOICES-XSS-CVE-2025-30915",
      "plugin_slug": "sliced-invoices",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-30915",
      "affected_versions": [
        "3.10.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30915",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLICEWP-XSS-CVE-2024-12731",
      "plugin_slug": "slicewp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12731",
      "affected_versions": [
        "1.2.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 80,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12731",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLIDER-VIDEO-RCE-CWE-94",
      "plugin_slug": "slider-video",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "1.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLIDER-VIDEO-RCE-CWE-95",
      "plugin_slug": "slider-video",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "1.5.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLIDER-WD-SSRF-CVE-2024-12682",
      "plugin_slug": "slider-wd",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2024-12682",
      "affected_versions": [
        "1.2.62"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12682",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLIDER-WD-SSRF-CVE-2024-12682",
      "plugin_slug": "slider-wd",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2024-12682",
      "affected_versions": [
        "1.2.62"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12682",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SLIMJETPACK-XSS-CWE-79",
      "plugin_slug": "slimjetpack",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.7.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMALL-PACKAGE-QUOTES-FEDEX-EDITION-SQLI-CWE-89",
      "plugin_slug": "small-package-quotes-fedex-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.3.23",
        "4.3.24",
        "4.3.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SMALL-PACKAGE-QUOTES-FEDEX-EDITION-SQLI-CWE-89",
      "plugin_slug": "small-package-quotes-fedex-edition",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.3.23",
        "4.3.24",
        "4.3.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 48,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SMALL-PACKAGE-QUOTES-FEDEX-EDITION-XSS-CWE-79",
      "plugin_slug": "small-package-quotes-fedex-edition",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3.24",
        "4.3.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 52,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-SMART-CATEGORIES-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "smart-categories-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-SMART-MARKETING-FOR-WP-SQLI-CWE-89",
      "plugin_slug": "smart-marketing-for-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.1.18",
        "5.1.21",
        "5.1.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SMART-MARKETING-FOR-WP-SQLI-CWE-89",
      "plugin_slug": "smart-marketing-for-wp",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.1.18",
        "5.1.21",
        "5.1.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SMART-MARKETING-FOR-WP-XSS-CWE-79",
      "plugin_slug": "smart-marketing-for-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.1.18",
        "5.1.21",
        "5.1.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 56,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SMART-TOOLS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "smart-tools-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMART-VARIATIONS-IMAGES-XSS-CWE-79",
      "plugin_slug": "smart-variations-images",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.2.29"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMARTPAY-XSS-CWE-79",
      "plugin_slug": "smartpay",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.0",
        "3.2.0",
        "3.2.1",
        "3.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMS-ALERT-RCE-CVE-2026-3640",
      "plugin_slug": "sms-alert",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2026-3640",
      "affected_versions": [
        "3.9.6",
        "3.9.7",
        "3.9.8"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3640",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMS-ALERT-RCE-CVE-2026-3640",
      "plugin_slug": "sms-alert",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "cve": "CVE-2026-3640",
      "affected_versions": [
        "3.9.6",
        "3.9.7",
        "3.9.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3640",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SMS-ALERT-XSS-CVE-2026-3640",
      "plugin_slug": "sms-alert",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-3640",
      "affected_versions": [
        "3.9.6",
        "3.9.7",
        "3.9.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3640",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SO-WIDGETS-BUNDLE-SQLI-CVE-2024-12018",
      "plugin_slug": "so-widgets-bundle",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-12018",
      "affected_versions": [
        "1.74.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12018",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-SO-WIDGETS-BUNDLE-SQLI-CVE-2024-12018",
      "plugin_slug": "so-widgets-bundle",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-12018",
      "affected_versions": [
        "1.74.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12018",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-SOCIAL-ENGINE-RCE-CVE-2008-3298",
      "plugin_slug": "social-engine",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2008-3298",
      "affected_versions": [
        "0.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2008-3298",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-SOCIAL-ENGINE-SQLI-CVE-2008-3297",
      "plugin_slug": "social-engine",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "medium",
      "cve": "CVE-2008-3297",
      "affected_versions": [
        "0.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2008-3297",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-SOCIAL-MEDIA-AUTO-PUBLISH-XSS-CWE-79",
      "plugin_slug": "social-media-auto-publish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.6.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SOCIAL-NETWORKS-AUTO-POSTER-FACEBOOK-TWITTER-G-XSS-CVE-2026-23798",
      "plugin_slug": "social-networks-auto-poster-facebook-twitter-g",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-23798",
      "affected_versions": [
        "4.4.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 50,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-23798",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SOCIAL-PROFILR-DISPLAY-SOCIAL-NETWORK-PROFILE-XSS-CVE-2025-62087",
      "plugin_slug": "social-profilr-display-social-network-profile",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62087",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62087",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SOCIAL-PUG-XSS-CVE-2025-0718",
      "plugin_slug": "social-pug",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-0718",
      "affected_versions": [
        "1.36.3",
        "1.36.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-0718",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SOCIAL-ROCKET-XSS-CVE-2024-13117",
      "plugin_slug": "social-rocket",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13117",
      "affected_versions": [
        "1.3.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13117",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SOFTACULOUS-KNOWN-CVE-CVE-2020-26886",
      "plugin_slug": "softaculous",
      "vuln_class": "known-cve",
      "cwe": "CWE-665",
      "severity": "high",
      "cve": "CVE-2020-26886",
      "affected_versions": [
        "2.4.0",
        "2.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2020-26886",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SPARK-GF-FAILED-SUBMISSIONS-XSS-CVE-2025-32497",
      "plugin_slug": "spark-gf-failed-submissions",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32497",
      "affected_versions": [
        "1.3.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32497",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SPEAKOUT-XSS-CWE-79",
      "plugin_slug": "speakout",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.6.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SPICE-BLOCKS-XSS-CVE-2025-48122",
      "plugin_slug": "spice-blocks",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48122",
      "affected_versions": [
        "2.0.7.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48122",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SPORTSPRESS-XSS-CWE-79",
      "plugin_slug": "sportspress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.7.31"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-SPROUT-CLIENTS-XSS-CVE-2026-39692",
      "plugin_slug": "sprout-clients",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39692",
      "affected_versions": [
        "3.2.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39692",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SPSS12-AB-LITE-TESTING-XSS-CWE-79",
      "plugin_slug": "spss12-ab-lite-testing",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-SQL-BUDDY-XSS-CVE-2014-4304",
      "plugin_slug": "sql-buddy",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2014-4304",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2014-4304",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-SQUAD-MODULES-FOR-DIVI-XSS-CWE-79",
      "plugin_slug": "squad-modules-for-divi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.4.0",
        "4.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-STAFFLIST-XSS-CWE-79",
      "plugin_slug": "stafflist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STAGGS-XSS-CWE-79",
      "plugin_slug": "staggs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STOCK-LOCATIONS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "stock-locations-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.0",
        "3.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-STOCKTAKE-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "stocktake-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.20",
        "1.1.21",
        "1.1.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 70,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-STONEHENGE-EM-OSM-SQLI-CWE-89",
      "plugin_slug": "stonehenge-em-osm",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STONEHENGE-EM-OSM-SQLI-CWE-89",
      "plugin_slug": "stonehenge-em-osm",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STONEHENGE-EM-OSM-XSS-CWE-79",
      "plugin_slug": "stonehenge-em-osm",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STOP-COMMENT-SPAM-XSS-CVE-2025-23883",
      "plugin_slug": "stop-comment-spam",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-23883",
      "affected_versions": [
        "0.5.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-23883",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-STOREENGINE-XSS-CVE-2025-10658",
      "plugin_slug": "storeengine",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-10658",
      "affected_versions": [
        "2.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10658",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-STORESHEET-XSS-CWE-79",
      "plugin_slug": "storesheet",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-STOREVOICEAI-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "storevoiceai-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.0.10",
        "0.0.11",
        "0.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-STREAMWEASELS-KICK-INTEGRATION-XSS-CVE-2025-60188",
      "plugin_slug": "streamweasels-kick-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-60188",
      "affected_versions": [
        "1.1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60188",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STREAMWEASELS-TWITCH-INTEGRATION-XSS-CWE-79",
      "plugin_slug": "streamweasels-twitch-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STREAMWEASELS-YOUTUBE-INTEGRATION-XSS-CWE-79",
      "plugin_slug": "streamweasels-youtube-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STRING-LOCATOR-XSS-CWE-79",
      "plugin_slug": "string-locator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-STYLE-MANAGER-XSS-CWE-79",
      "plugin_slug": "style-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.1",
        "2.3.2",
        "2.4.0",
        "2.4.1",
        "2.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 120,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUBACCOUNTS-FOR-WOOCOMMERCE-XSS-CVE-2025-4317",
      "plugin_slug": "subaccounts-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-4317",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4317",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-BROKEN-ACCESS-CONTROL-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-284",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-BROKEN-ACCESS-CONTROL-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-BROKEN-ACCESS-CONTROL-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 7,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-CSRF-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-DESERIALIZATION-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "critical",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-DESERIALIZATION-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-KNOWN-CVE-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-KNOWN-CVE-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "known-cve",
      "cwe": "CWE-620",
      "severity": "high",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-KNOWN-CVE-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-OPEN-REDIRECT-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "open-redirect",
      "cwe": "CWE-601",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-SQLI-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-SQLI-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-SSRF-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-SSRF-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUNSHINE-PHOTO-CART-XSS-CVE-2025-68035",
      "plugin_slug": "sunshine-photo-cart",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68035",
      "affected_versions": [
        "2.4.4",
        "3.2",
        "3.6.11"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68035",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUPERVISOR-KNOWN-CVE-CVE-2025-6680",
      "plugin_slug": "supervisor",
      "vuln_class": "known-cve",
      "cwe": "CWE-276",
      "severity": "high",
      "cve": "CVE-2025-6680",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6680",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUPERVISOR-KNOWN-CVE-CVE-2025-6680",
      "plugin_slug": "supervisor",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "critical",
      "cve": "CVE-2025-6680",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6680",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SUPERVISOR-KNOWN-CVE-CVE-2025-6680",
      "plugin_slug": "supervisor",
      "vuln_class": "known-cve",
      "cwe": "CWE-306",
      "severity": "high",
      "cve": "CVE-2025-6680",
      "affected_versions": [
        "1.3.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6680",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SURFERSEO-XSS-CVE-2025-59011",
      "plugin_slug": "surferseo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-59011",
      "affected_versions": [
        "1.7.0.639"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-59011",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SURFLINK-XSS-CWE-79",
      "plugin_slug": "surflink",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-27"
    },
    {
      "id": "CLR-WP-SWIFT-PERFORMANCE-LITE-SSRF-CVE-2024-54216",
      "plugin_slug": "swift-performance-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2024-54216",
      "affected_versions": [
        "2.3.7.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54216",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SWIFT-PERFORMANCE-LITE-SSRF-CVE-2024-54216",
      "plugin_slug": "swift-performance-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2024-54216",
      "affected_versions": [
        "2.3.7.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54216",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SWIFT-PERFORMANCE-LITE-XSS-CVE-2024-54216",
      "plugin_slug": "swift-performance-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54216",
      "affected_versions": [
        "2.3.7.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54216",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-SYNERGY-PROJECT-MANAGER-XSS-CVE-2025-14615",
      "plugin_slug": "synergy-project-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-14615",
      "affected_versions": [
        "1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14615",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TABLE-OF-CONTENTS-CREATOR-XSS-CWE-79",
      "plugin_slug": "table-of-contents-creator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.4.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TABLEPRESS-XSS-CVE-2025-4594",
      "plugin_slug": "tablepress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-4594",
      "affected_versions": [
        "3.3.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4594",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TAILORED-TOOLS-XSS-CWE-79",
      "plugin_slug": "tailored-tools",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.8.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TAX-EXEMPTION-WOO-XSS-CWE-79",
      "plugin_slug": "tax-exemption-woo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-TAXONOMY-SWITCHER-XSS-CWE-79",
      "plugin_slug": "taxonomy-switcher",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-TEACHPRESS-XSS-CWE-79",
      "plugin_slug": "teachpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.0.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TEAM-BROKEN-ACCESS-CONTROL-CVE-2024-13439",
      "plugin_slug": "team",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2024-13439",
      "affected_versions": [
        "1.22.28"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13439",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TEAM-FREE-XSS-CWE-79",
      "plugin_slug": "team-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TEAM-ROSTERS-XSS-CVE-2025-25118",
      "plugin_slug": "team-rosters",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-25118",
      "affected_versions": [
        "2.0"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-25118",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-TEAM-SHOWCASE-SUPREME-SQLI-CWE-89",
      "plugin_slug": "team-showcase-supreme",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "8.9",
        "9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 36,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-TEAM-SHOWCASE-SUPREME-SQLI-CWE-89",
      "plugin_slug": "team-showcase-supreme",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "8.9",
        "9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-TELEGRAM-BOT-XSS-CWE-79",
      "plugin_slug": "telegram-bot",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TEMPLATESPARE-XSS-CWE-79",
      "plugin_slug": "templatespare",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TENWEB-SPEED-OPTIMIZER-XSS-CWE-79",
      "plugin_slug": "tenweb-speed-optimizer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.33.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TERMS-AND-CONDITIONS-PER-PRODUCT-XSS-CWE-79",
      "plugin_slug": "terms-and-conditions-per-product",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TERMS-DESCRIPTIONS-SQLI-CWE-89",
      "plugin_slug": "terms-descriptions",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.4.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TERMS-DESCRIPTIONS-SQLI-CWE-89",
      "plugin_slug": "terms-descriptions",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.4.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TERMS-DESCRIPTIONS-XSS-CWE-79",
      "plugin_slug": "terms-descriptions",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TERMS-DICTIONARY-XSS-CWE-79",
      "plugin_slug": "terms-dictionary",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TESTIMONIAL-FREE-XSS-CVE-2026-13080",
      "plugin_slug": "testimonial-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-13080",
      "affected_versions": [
        "3.1.16"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-13080",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-THE-EVENTS-CALENDAR-XSS-CVE-2025-22562",
      "plugin_slug": "the-events-calendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-22562",
      "affected_versions": [
        "6.17.0",
        "6.17.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22562",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THEATRE-XSS-CVE-2025-68569",
      "plugin_slug": "theatre",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68569",
      "affected_versions": [
        "0.19.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68569",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-THEME-BLVD-LAYOUT-BUILDER-XSS-CWE-79",
      "plugin_slug": "theme-blvd-layout-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THEMESFLAT-ADDONS-FOR-ELEMENTOR-XSS-CWE-79",
      "plugin_slug": "themesflat-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-THEMIFY-WC-PRODUCT-FILTER-XSS-CWE-79",
      "plugin_slug": "themify-wc-product-filter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-THIMPRESS-CLASS-MANAGER-SSRF-CWE-918",
      "plugin_slug": "thimpress-class-manager",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THIMPRESS-CLASS-MANAGER-SSRF-CWE-918",
      "plugin_slug": "thimpress-class-manager",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THIS-SEO-XSS-CWE-79",
      "plugin_slug": "this-seo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THROWS-SPAM-AWAY-SQLI-CWE-89",
      "plugin_slug": "throws-spam-away",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-THROWS-SPAM-AWAY-SQLI-CWE-89",
      "plugin_slug": "throws-spam-away",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TICKET-HAWKER-XSS-CWE-79",
      "plugin_slug": "ticket-hawker",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-14"
    },
    {
      "id": "CLR-WP-TICKET-HELP-DESK-SYSTEM-LITE-SQLI-CWE-89",
      "plugin_slug": "ticket-help-desk-system-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 22,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TICKET-HELP-DESK-SYSTEM-LITE-SQLI-CWE-89",
      "plugin_slug": "ticket-help-desk-system-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 99,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TICKET-HELP-DESK-SYSTEM-LITE-XSS-CWE-79",
      "plugin_slug": "ticket-help-desk-system-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TIER-PRICING-TABLE-XSS-CWE-79",
      "plugin_slug": "tier-pricing-table",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.5.0",
        "7.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TIMELINE-PRO-XSS-CVE-2024-12505",
      "plugin_slug": "timeline-pro",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12505",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12505",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TINYNAV-XSS-CVE-2025-49972",
      "plugin_slug": "tinynav",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49972",
      "affected_versions": [
        "1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49972",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TOOLBOX-FOR-ASGAROS-FORUM-XSS-CWE-79",
      "plugin_slug": "toolbox-for-asgaros-forum",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TOURNAMATCH-XSS-CWE-79",
      "plugin_slug": "tournamatch",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TOURNAMATCH-XSS-CVE-2024-5627",
      "plugin_slug": "tournamatch",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-5627",
      "affected_versions": [
        "4.7.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-5627",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TRACKSERVER-XSS-CWE-79",
      "plugin_slug": "trackserver",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TRAININGPRESS-XSS-CWE-79",
      "plugin_slug": "trainingpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 42,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TRANSIENTS-MANAGER-XSS-CWE-79",
      "plugin_slug": "transients-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-TRUEBOOKER-APPOINTMENT-BOOKING-XSS-CVE-2025-68565",
      "plugin_slug": "truebooker-appointment-booking",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68565",
      "affected_versions": [
        "1.2.4",
        "1.2.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 59,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68565",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TUNE-LIBRARY-SQLI-CWE-89",
      "plugin_slug": "tune-library",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TUNE-LIBRARY-SQLI-CWE-89",
      "plugin_slug": "tune-library",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-TUTOR-XSS-CVE-2026-3396",
      "plugin_slug": "tutor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-3396",
      "affected_versions": [
        "4.0.0",
        "4.0.2",
        "4.0.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 40,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3396",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-TWITTER-AUTO-PUBLISH-XSS-CWE-79",
      "plugin_slug": "twitter-auto-publish",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-TYPING-TEXT-XSS-CVE-2025-22315",
      "plugin_slug": "typing-text",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-22315",
      "affected_versions": [
        "1.2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-22315",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-UBER-MEDIA-XSS-CWE-79",
      "plugin_slug": "uber-media",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-UGCIFY-XSS-CWE-79",
      "plugin_slug": "ugcify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-ULISTING-BROKEN-ACCESS-CONTROL-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-CSRF-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-KNOWN-CVE-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "known-cve",
      "cwe": "CWE-264",
      "severity": "critical",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-KNOWN-CVE-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "known-cve",
      "cwe": "CWE-266",
      "severity": "high",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-KNOWN-CVE-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "high",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-SQLI-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULISTING-XSS-CVE-2025-39402",
      "plugin_slug": "ulisting",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-39402",
      "affected_versions": [
        "1.7.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-39402",
      "first_seen": "2026-07-24"
    },
    {
      "id": "CLR-WP-ULTIMAKIT-FOR-WP-XSS-CWE-79",
      "plugin_slug": "ultimakit-for-wp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ULTIMATE-ADDONS-FOR-CONTACT-FORM-7-XSS-CVE-2025-66125",
      "plugin_slug": "ultimate-addons-for-contact-form-7",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-66125",
      "affected_versions": [
        "3.5.45",
        "3.5.46",
        "3.5.47"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-66125",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ULTIMATE-BLOCKS-XSS-CVE-2025-4775",
      "plugin_slug": "ultimate-blocks",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-4775",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-4775",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ULTIMATE-BOOTSTRAP-ELEMENTS-FOR-ELEMENTOR-XSS-CVE-2025-32587",
      "plugin_slug": "ultimate-bootstrap-elements-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32587",
      "affected_versions": [
        "1.5.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32587",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ULTIMATE-CLASSIFIED-LISTINGS-CSRF-CVE-2025-27302",
      "plugin_slug": "ultimate-classified-listings",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-27302",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27302",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-ULTIMATE-CLASSIFIED-LISTINGS-LFI-CVE-2025-27302",
      "plugin_slug": "ultimate-classified-listings",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "high",
      "cve": "CVE-2025-27302",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27302",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-ULTIMATE-CLASSIFIED-LISTINGS-XSS-CVE-2025-27302",
      "plugin_slug": "ultimate-classified-listings",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-27302",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27302",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-ULTIMATE-CLASSIFIED-LISTINGS-XSS-CVE-2025-27302",
      "plugin_slug": "ultimate-classified-listings",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-27302",
      "affected_versions": [
        "1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-27302",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-ULTIMATE-FORMS-XSS-CWE-79",
      "plugin_slug": "ultimate-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ULTIMATE-INFINITE-SCROLL-XSS-CWE-79",
      "plugin_slug": "ultimate-infinite-scroll",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ULTIMATE-MEMBER-XSS-CVE-2025-2111",
      "plugin_slug": "ultimate-member",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-2111",
      "affected_versions": [
        "2.12.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2111",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ULTIMATE-STORE-KIT-XSS-CVE-2025-66149",
      "plugin_slug": "ultimate-store-kit",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-66149",
      "affected_versions": [
        "3.0.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-66149",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ULTIMATE-WP-MAIL-XSS-CVE-2025-32612",
      "plugin_slug": "ultimate-wp-mail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32612",
      "affected_versions": [
        "1.3.12",
        "1.3.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32612",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-ULTRA-ADDONS-FOR-WPFORMS-SSRF-CVE-2025-53444",
      "plugin_slug": "ultra-addons-for-wpforms",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-53444",
      "affected_versions": [
        "1.1.0",
        "1.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53444",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ULTRA-ADDONS-FOR-WPFORMS-SSRF-CVE-2025-53444",
      "plugin_slug": "ultra-addons-for-wpforms",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-53444",
      "affected_versions": [
        "1.1.0",
        "1.1.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53444",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-UNIFY-SSRF-CVE-2025-62910",
      "plugin_slug": "unify",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-62910",
      "affected_versions": [
        "3.4.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62910",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-UNIFY-SSRF-CVE-2025-62910",
      "plugin_slug": "unify",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-62910",
      "affected_versions": [
        "3.4.10"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62910",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-UPDATE-URLS-XSS-CVE-2026-25428",
      "plugin_slug": "update-urls",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25428",
      "affected_versions": [
        "1.4.6",
        "1.4.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25428",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-UPDRAFTPLUS-BROKEN-ACCESS-CONTROL-CVE-2024-12293",
      "plugin_slug": "updraftplus",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2024-12293",
      "affected_versions": [
        "1.26.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12293",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-UPDRAFTPLUS-BROKEN-ACCESS-CONTROL-CVE-2024-12293",
      "plugin_slug": "updraftplus",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-863",
      "severity": "medium",
      "cve": "CVE-2024-12293",
      "affected_versions": [
        "1.26.5",
        "1.26.6"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12293",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-URL-SHORTIFY-XSS-CVE-2025-2874",
      "plugin_slug": "url-shortify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-2874",
      "affected_versions": [
        "2.4.1",
        "2.4.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2874",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-USC-E-SHOP-XSS-CVE-2025-10749",
      "plugin_slug": "usc-e-shop",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-10749",
      "affected_versions": [
        "2.11.31"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-10749",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-USER-AVATAR-RELOADED-XSS-CVE-2025-58257",
      "plugin_slug": "user-avatar-reloaded",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58257",
      "affected_versions": [
        "1.2.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58257",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-BROKEN-ACCESS-CONTROL-CVE-2026-0811",
      "plugin_slug": "user-registration",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2026-0811",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0811",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-DESERIALIZATION-CVE-2026-0811",
      "plugin_slug": "user-registration",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-0811",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0811",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-FILE-UPLOAD-CVE-2026-0811",
      "plugin_slug": "user-registration",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2026-0811",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0811",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-FILE-UPLOAD-CVE-2026-0811",
      "plugin_slug": "user-registration",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "high",
      "cve": "CVE-2026-0811",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0811",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-SSRF-CVE-2026-4001",
      "plugin_slug": "user-registration",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-4001",
      "affected_versions": [
        "5.2.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4001",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-SSRF-CVE-2026-4001",
      "plugin_slug": "user-registration",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-4001",
      "affected_versions": [
        "5.2.6"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4001",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-XSS-CVE-2026-4001",
      "plugin_slug": "user-registration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-4001",
      "affected_versions": [
        "5.2.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4001",
      "first_seen": "2026-07-23"
    },
    {
      "id": "CLR-WP-USER-REGISTRATION-XSS-CVE-2026-0811",
      "plugin_slug": "user-registration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-0811",
      "affected_versions": [
        "1.4.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-0811",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-V-FORM-SSRF-CWE-918",
      "plugin_slug": "v-form",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.2.33"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-V-FORM-SSRF-CWE-918",
      "plugin_slug": "v-form",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.2.33"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-V-FORM-XSS-CWE-79",
      "plugin_slug": "v-form",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.32",
        "3.2.33",
        "3.2.34"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 146,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VAMPIRE-CHARACTER-SQLI-CWE-89",
      "plugin_slug": "vampire-character",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VAMPIRE-CHARACTER-SQLI-CWE-89",
      "plugin_slug": "vampire-character",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.15"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 47,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VAYU-BLOCKS-XSS-CVE-2024-13338",
      "plugin_slug": "vayu-blocks",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-13338",
      "affected_versions": [
        "1.4.3"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13338",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-VERGE3D-XSS-CVE-2025-5082",
      "plugin_slug": "verge3d",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-5082",
      "affected_versions": [
        "4.12.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-5082",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VEROWA-CONNECT-XSS-CVE-2024-51615",
      "plugin_slug": "verowa-connect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-51615",
      "affected_versions": [
        "3.5.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-51615",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VIDEO-COMMENTS-WEBCAM-RECORDER-XSS-CWE-79",
      "plugin_slug": "video-comments-webcam-recorder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-18"
    },
    {
      "id": "CLR-WP-VIDEO-LIST-MANAGER-KNOWN-CVE-CVE-2025-52822",
      "plugin_slug": "video-list-manager",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2025-52822",
      "affected_versions": [
        "1.7"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-52822",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VIDEO-POSTS-WEBCAM-RECORDER-XSS-CWE-79",
      "plugin_slug": "video-posts-webcam-recorder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.4.1",
        "3.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "first_seen": "2026-07-18"
    },
    {
      "id": "CLR-WP-VIDEO-SHARE-VOD-XSS-CVE-2024-12622",
      "plugin_slug": "video-share-vod",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12622",
      "affected_versions": [
        "3.1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12622",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VIDEOWHISPER-LIVE-STREAMING-INTEGRATION-SQLI-CWE-89",
      "plugin_slug": "videowhisper-live-streaming-integration",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "7.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VIDEOWHISPER-LIVE-STREAMING-INTEGRATION-SQLI-CWE-89",
      "plugin_slug": "videowhisper-live-streaming-integration",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "7.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VIDEOWHISPER-LIVE-STREAMING-INTEGRATION-XSS-CWE-79",
      "plugin_slug": "videowhisper-live-streaming-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 52,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VIEWMEDICA-XSS-CVE-2024-13094",
      "plugin_slug": "viewmedica",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13094",
      "affected_versions": [
        "1.4.21"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13094",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VIEWS-FOR-NINJA-FORMS-XSS-CWE-79",
      "plugin_slug": "views-for-ninja-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VISA-ACCEPTANCE-SOLUTIONS-XSS-CWE-79",
      "plugin_slug": "visa-acceptance-solutions",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VISITORS-TRAFFIC-REAL-TIME-STATISTICS-SQLI-CWE-89",
      "plugin_slug": "visitors-traffic-real-time-statistics",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "8.12",
        "8.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-VISITORS-TRAFFIC-REAL-TIME-STATISTICS-SQLI-CWE-89",
      "plugin_slug": "visitors-traffic-real-time-statistics",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "8.12",
        "8.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-08-02"
    },
    {
      "id": "CLR-WP-VISITORS-TRAFFIC-REAL-TIME-STATISTICS-XSS-CWE-79",
      "plugin_slug": "visitors-traffic-real-time-statistics",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.11",
        "8.12",
        "8.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 48,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-VIVIO-SWIFT-XSS-CWE-79",
      "plugin_slug": "vivio-swift",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2020040301"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VK-FILTER-SEARCH-XSS-CWE-79",
      "plugin_slug": "vk-filter-search",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.20.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VMPFENCE-SECURITY-SSRF-CWE-918",
      "plugin_slug": "vmpfence-security",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.3.8",
        "2.3.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-VMPFENCE-SECURITY-SSRF-CWE-918",
      "plugin_slug": "vmpfence-security",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.3.8",
        "2.3.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 46,
      "action": "warn",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-VOD-INFOMANIAK-XSS-CVE-2025-9816",
      "plugin_slug": "vod-infomaniak",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-9816",
      "affected_versions": [
        "1.5.14"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-9816",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-VOIDEK-SERP-SCHEMA-BUILDER-XSS-CWE-79",
      "plugin_slug": "voidek-serp-schema-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-VOTING-FOR-A-PHOTO-SQLI-CWE-89",
      "plugin_slug": "voting-for-a-photo",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VOTING-FOR-A-PHOTO-SQLI-CWE-89",
      "plugin_slug": "voting-for-a-photo",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-VOUCHERPRESS-XSS-CVE-2025-8902",
      "plugin_slug": "voucherpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-8902",
      "affected_versions": [
        "1.5.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 41,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8902",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-W2S-SYNC-SSRF-CWE-918",
      "plugin_slug": "w2s-sync",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-W2S-SYNC-SSRF-CWE-918",
      "plugin_slug": "w2s-sync",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-W3-TOTAL-CACHE-BROKEN-ACCESS-CONTROL-CVE-2026-27389",
      "plugin_slug": "w3-total-cache",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "high",
      "cve": "CVE-2026-27389",
      "affected_versions": [
        "0.15.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27389",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-W3-TOTAL-CACHE-BROKEN-ACCESS-CONTROL-CVE-2026-27389",
      "plugin_slug": "w3-total-cache",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2026-27389",
      "affected_versions": [
        "0.15.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27389",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-W3-TOTAL-CACHE-KNOWN-CVE-CVE-2026-27389",
      "plugin_slug": "w3-total-cache",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "low",
      "cve": "CVE-2026-27389",
      "affected_versions": [
        "0.15.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27389",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-W3-TOTAL-CACHE-KNOWN-CVE-CVE-2026-27389",
      "plugin_slug": "w3-total-cache",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2026-27389",
      "affected_versions": [
        "0.15.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27389",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-W3-TOTAL-CACHE-XSS-CVE-2026-27389",
      "plugin_slug": "w3-total-cache",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-27389",
      "affected_versions": [
        "0.15.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-27389",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-W3S-CF7-ZOHO-XSS-CVE-2025-58246",
      "plugin_slug": "w3s-cf7-zoho",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58246",
      "affected_versions": [
        "3.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58246",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-W9-1099-CHASER-SSRF-CWE-918",
      "plugin_slug": "w9-1099-chaser",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-W9-1099-CHASER-SSRF-CWE-918",
      "plugin_slug": "w9-1099-chaser",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.0.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WALKER-CORE-XSS-CVE-2025-67551",
      "plugin_slug": "walker-core",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67551",
      "affected_versions": [
        "1.3.18"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67551",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WATU-SQLI-CVE-2025-54004",
      "plugin_slug": "watu",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-54004",
      "affected_versions": [
        "3.4.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54004",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WATU-SQLI-CVE-2025-54004",
      "plugin_slug": "watu",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-54004",
      "affected_versions": [
        "3.4.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54004",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WATU-XSS-CVE-2025-54004",
      "plugin_slug": "watu",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-54004",
      "affected_versions": [
        "3.4.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 31,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54004",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-DISABLE-ZOOM-LIGHTBOX-FEATURES-XSS-CWE-79",
      "plugin_slug": "wc-disable-zoom-lightbox-features",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-MULTISHIPPING-XSS-CWE-79",
      "plugin_slug": "wc-multishipping",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-PEACH-PAYMENTS-GATEWAY-XSS-CWE-79",
      "plugin_slug": "wc-peach-payments-gateway",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.5",
        "4.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-PRODUCT-TABLE-LITE-XSS-CVE-2025-3104",
      "plugin_slug": "wc-product-table-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-3104",
      "affected_versions": [
        "5.1.0",
        "5.4.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-3104",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-REPORTS-LITE-SQLI-CWE-89",
      "plugin_slug": "wc-reports-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WC-REPORTS-LITE-SQLI-CWE-89",
      "plugin_slug": "wc-reports-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WC-SHIP-EST-XSS-CWE-79",
      "plugin_slug": "wc-ship-est",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.20"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "first_seen": "2026-07-22"
    },
    {
      "id": "CLR-WP-WC-ZELLE-XSS-CWE-79",
      "plugin_slug": "wc-zelle",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WC-ZOHO-INVENTORY-XSS-CWE-79",
      "plugin_slug": "wc-zoho-inventory",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-30"
    },
    {
      "id": "CLR-WP-WC4BP-XSS-CWE-79",
      "plugin_slug": "wc4bp",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WDESIGNKIT-SSRF-CWE-918",
      "plugin_slug": "wdesignkit",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.5.5",
        "2.6.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WDESIGNKIT-SSRF-CWE-918",
      "plugin_slug": "wdesignkit",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.5.5",
        "2.6.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WEB-DIRECTORY-FREE-SSRF-CVE-2025-32602",
      "plugin_slug": "web-directory-free",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-32602",
      "affected_versions": [
        "1.7.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32602",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEB-DIRECTORY-FREE-SSRF-CVE-2025-32602",
      "plugin_slug": "web-directory-free",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-32602",
      "affected_versions": [
        "1.7.13"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32602",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEB-DIRECTORY-FREE-XSS-CVE-2025-32602",
      "plugin_slug": "web-directory-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32602",
      "affected_versions": [
        "1.7.13"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 82,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32602",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-BROKEN-ACCESS-CONTROL-CVE-2023-33922",
      "plugin_slug": "website-builder",
      "vuln_class": "broken-access-control",
      "cwe": "CWE-862",
      "severity": "medium",
      "cve": "CVE-2023-33922",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-33922",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-KNOWN-CVE-CVE-2023-0329",
      "plugin_slug": "website-builder",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2023-0329",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-0329",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-KNOWN-CVE-CVE-2022-4953",
      "plugin_slug": "website-builder",
      "vuln_class": "known-cve",
      "severity": "medium",
      "cve": "CVE-2022-4953",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-4953",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-KNOWN-CVE-CVE-2024-6757",
      "plugin_slug": "website-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2024-6757",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-6757",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-KNOWN-CVE-CVE-2024-8494",
      "plugin_slug": "website-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-200",
      "severity": "medium",
      "cve": "CVE-2024-8494",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8494",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-KNOWN-CVE-CVE-2023-47504",
      "plugin_slug": "website-builder",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "medium",
      "cve": "CVE-2023-47504",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-47504",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-LFI-CVE-2024-24934",
      "plugin_slug": "website-builder",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "high",
      "cve": "CVE-2024-24934",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-24934",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-LFI-CVE-2025-8081",
      "plugin_slug": "website-builder",
      "vuln_class": "lfi",
      "cwe": "CWE-22",
      "severity": "medium",
      "cve": "CVE-2025-8081",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-8081",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2020-36171",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2020-36171",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2020-36171",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24201",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24201",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24201",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24202",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24202",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24202",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24203",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24203",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24203",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24204",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24204",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24204",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24205",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24205",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24205",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24206",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24206",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24206",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2021-24891",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2021-24891",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2021-24891",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2022-29455",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2022-29455",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-29455",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2023-47505",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2023-47505",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-47505",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-0506",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-0506",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-0506",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-10453",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-10453",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-10453",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-13445",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-13445",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13445",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-2117",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-2117",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-2117",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-2120",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-2120",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-2120",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-37437",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-37437",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-37437",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-4107",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-4107",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-4107",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-4619",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-4619",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-4619",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-5416",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-5416",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-5416",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-54444",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-54444",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54444",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2024-8236",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2024-8236",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-8236",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSITE-BUILDER-XSS-CVE-2025-3075",
      "plugin_slug": "website-builder",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-3075",
      "affected_versions": [
        "3.0.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-3075",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBSPELLCHECKER-XSS-CVE-2020-9440",
      "plugin_slug": "webspellchecker",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2020-9440",
      "affected_versions": [
        "3.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2020-9440",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WEBTEXTTOOL-XSS-CVE-2025-15043",
      "plugin_slug": "webtexttool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-15043",
      "affected_versions": [
        "3.6.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-15043",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBTOFFEE-PRODUCT-FEED-SSRF-CWE-918",
      "plugin_slug": "webtoffee-product-feed",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WEBTOFFEE-PRODUCT-FEED-SSRF-CWE-918",
      "plugin_slug": "webtoffee-product-feed",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "2.4.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WGRANK-MULTILINGUAL-XSS-CWE-79",
      "plugin_slug": "wgrank-multilingual",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.2",
        "1.0.3",
        "1.0.4",
        "1.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WHIPPET-SSRF-CWE-918",
      "plugin_slug": "whippet",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.1.0",
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-WHIPPET-SSRF-CWE-918",
      "plugin_slug": "whippet",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.1.0",
        "1.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-12"
    },
    {
      "id": "CLR-WP-WHOLS-XSS-CWE-79",
      "plugin_slug": "whols",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WIDGET-GOOGLE-REVIEWS-XSS-CWE-79",
      "plugin_slug": "widget-google-reviews",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.9.10",
        "6.9.8",
        "6.9.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WIDGETIZE-PAGES-LIGHT-XSS-CWE-79",
      "plugin_slug": "widgetize-pages-light",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WIDGETS-ON-PAGES-XSS-CWE-79",
      "plugin_slug": "widgets-on-pages",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.9.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WIP-INCOMING-LITE-XSS-CWE-79",
      "plugin_slug": "wip-incoming-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WIP-WOOCAROUSEL-LITE-XSS-CVE-2024-54213",
      "plugin_slug": "wip-woocarousel-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-54213",
      "affected_versions": [
        "1.1.9",
        "1.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-54213",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WIRED-IMPACT-VOLUNTEER-MANAGEMENT-XSS-CWE-79",
      "plugin_slug": "wired-impact-volunteer-management",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8.1",
        "2.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WISHLIST-CSRF-CVE-2025-47570",
      "plugin_slug": "wishlist",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2025-47570",
      "affected_versions": [
        "1.0.46"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47570",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WISHLIST-CSRF-CVE-2025-47570",
      "plugin_slug": "wishlist",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "medium",
      "cve": "CVE-2025-47570",
      "affected_versions": [
        "1.0.46"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47570",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WISHLIST-XSS-CVE-2025-47570",
      "plugin_slug": "wishlist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-47570",
      "affected_versions": [
        "1.0.46"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47570",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WISHLIST-XSS-CVE-2025-47570",
      "plugin_slug": "wishlist",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-47570",
      "affected_versions": [
        "1.0.46"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-47570",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WONDERPLUGIN-SLIDER-LITE-XSS-CWE-79",
      "plugin_slug": "wonderplugin-slider-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "14.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WONDERPLUGIN-VIDEO-EMBED-XSS-CWE-79",
      "plugin_slug": "wonderplugin-video-embed",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-ADD-CUSTOM-FEE-XSS-CWE-79",
      "plugin_slug": "woo-add-custom-fee",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.7.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-WOO-ADD-TO-QUOTE-XSS-CWE-79",
      "plugin_slug": "woo-add-to-quote",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-16"
    },
    {
      "id": "CLR-WP-WOO-ADDITIONAL-FEES-ON-CHECKOUT-WORDPRESS-XSS-CVE-2024-56265",
      "plugin_slug": "woo-additional-fees-on-checkout-wordpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56265",
      "affected_versions": [
        "1.5.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 32,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56265",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-ADVANCED-PRODUCT-SIZE-CHART-XSS-CWE-79",
      "plugin_slug": "woo-advanced-product-size-chart",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-AUTHORIZE-NET-GATEWAY-AIM-XSS-CWE-79",
      "plugin_slug": "woo-authorize-net-gateway-aim",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.1.26"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-BLOCKER-LITE-PREVENT-FAKE-ORDERS-AND-BLACKLIST-FRAUD-CUSTOMERS-SSRF-CVE-2026-4373",
      "plugin_slug": "woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2026-4373",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-BLOCKER-LITE-PREVENT-FAKE-ORDERS-AND-BLACKLIST-FRAUD-CUSTOMERS-SSRF-CVE-2026-4373",
      "plugin_slug": "woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2026-4373",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-BLOCKER-LITE-PREVENT-FAKE-ORDERS-AND-BLACKLIST-FRAUD-CUSTOMERS-XSS-CVE-2026-4373",
      "plugin_slug": "woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-4373",
      "affected_versions": [
        "2.3.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-CHECKOUT-FOR-DIGITAL-GOODS-XSS-CWE-79",
      "plugin_slug": "woo-checkout-for-digital-goods",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-CLASSEMENT-XSS-CWE-79",
      "plugin_slug": "woo-classement",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.7.3.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-WOO-CONDITIONAL-PRODUCT-FEES-FOR-CHECKOUT-XSS-CWE-79",
      "plugin_slug": "woo-conditional-product-fees-for-checkout",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-COUPON-USAGE-XSS-CWE-79",
      "plugin_slug": "woo-coupon-usage",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.8.2",
        "8.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 50,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-CUSTOMERS-MANAGER-XSS-CVE-2025-13504",
      "plugin_slug": "woo-customers-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-13504",
      "affected_versions": [
        "1.1.16"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-13504",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-ECOMMERCE-TRACKING-FOR-GOOGLE-AND-FACEBOOK-XSS-CWE-79",
      "plugin_slug": "woo-ecommerce-tracking-for-google-and-facebook",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-ORDER-SPLITTER-SQLI-CWE-89",
      "plugin_slug": "woo-order-splitter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-ORDER-SPLITTER-SQLI-CWE-89",
      "plugin_slug": "woo-order-splitter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.3.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-PERMALINK-MANAGER-XSS-CWE-79",
      "plugin_slug": "woo-permalink-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOO-PRODUCT-ATTACHMENT-XSS-CWE-79",
      "plugin_slug": "woo-product-attachment",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-WOO-PRODUCT-VARIATION-SWATCHES-XSS-CWE-79",
      "plugin_slug": "woo-product-variation-swatches",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.23"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOO-RAZORPAY-SQLI-CVE-2025-14444",
      "plugin_slug": "woo-razorpay",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-14444",
      "affected_versions": [
        "4.8.6",
        "4.8.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14444",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-RAZORPAY-SQLI-CVE-2025-14444",
      "plugin_slug": "woo-razorpay",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-14444",
      "affected_versions": [
        "4.8.6",
        "4.8.7"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-14444",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-SET-PRICE-NOTE-XSS-CWE-79",
      "plugin_slug": "woo-set-price-note",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 31,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-WOO-THANK-YOU-PAGE-NEXTMOVE-LITE-XSS-CVE-2026-7209",
      "plugin_slug": "woo-thank-you-page-nextmove-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-7209",
      "affected_versions": [
        "2.24.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-7209",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOO-WHOLESALE-PRICING-XSS-CWE-79",
      "plugin_slug": "woo-wholesale-pricing",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.5",
        "2.0.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 36,
      "action": "block",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-COUNTRY-BASED-PAYMENTS-XSS-CWE-79",
      "plugin_slug": "woocommerce-country-based-payments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-CURRENCY-SWITCHER-XSS-CVE-2026-56040",
      "plugin_slug": "woocommerce-currency-switcher",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-56040",
      "affected_versions": [
        "1.4.9",
        "1.5.0",
        "1.5.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-56040",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-DELIVERY-DATE-XSS-CWE-79",
      "plugin_slug": "woocommerce-delivery-date",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.0.1",
        "3.0.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-GATEWAY-STRIPE-XSS-CWE-79",
      "plugin_slug": "woocommerce-gateway-stripe",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "10.8.3",
        "10.8.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-GERMANIZED-XSS-CWE-79",
      "plugin_slug": "woocommerce-germanized",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.10"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-JNE-XSS-CWE-79",
      "plugin_slug": "woocommerce-jne",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "9.2.33",
        "9.2.34",
        "9.2.35"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-PAY-PER-POST-XSS-CWE-79",
      "plugin_slug": "woocommerce-pay-per-post",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2.34"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-08-01"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-PAYPAL-PAYMENTS-XSS-CWE-79",
      "plugin_slug": "woocommerce-paypal-payments",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-PRODUCTS-FILTER-KNOWN-CVE-CVE-2025-62736",
      "plugin_slug": "woocommerce-products-filter",
      "vuln_class": "known-cve",
      "cwe": "CWE-20",
      "severity": "critical",
      "cve": "CVE-2025-62736",
      "affected_versions": [
        "1.4.0",
        "1.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62736",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-PRODUCTS-FILTER-KNOWN-CVE-CVE-2025-62736",
      "plugin_slug": "woocommerce-products-filter",
      "vuln_class": "known-cve",
      "cwe": "CWE-287",
      "severity": "critical",
      "cve": "CVE-2025-62736",
      "affected_versions": [
        "1.4.0",
        "1.4.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62736",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-STOCK-MANAGER-XSS-CVE-2026-24636",
      "plugin_slug": "woocommerce-stock-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-24636",
      "affected_versions": [
        "3.8.0",
        "3.9.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-24636",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOOCOMMERCE-SUPERFAKTURA-XSS-CWE-79",
      "plugin_slug": "woocommerce-superfaktura",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.53.1",
        "1.53.2",
        "1.53.5",
        "1.53.6",
        "1.53.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOOCUSTOMIZER-XSS-CVE-2026-25454",
      "plugin_slug": "woocustomizer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-25454",
      "affected_versions": [
        "2.6.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-25454",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOOPOP-ELECTRONIC-INVOICE-FREE-XSS-CWE-79",
      "plugin_slug": "woopop-electronic-invoice-free",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.9.10",
        "6.9.7",
        "6.9.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOOROUSELL-XSS-CWE-79",
      "plugin_slug": "woorousell",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOOSQUARE-XSS-CWE-79",
      "plugin_slug": "woosquare",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.7.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOOSTIFY-SITES-LIBRARY-XSS-CWE-79",
      "plugin_slug": "woostify-sites-library",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOOWBOT-WOOCOMMERCE-CHATBOT-SQLI-CVE-2026-12123",
      "plugin_slug": "woowbot-woocommerce-chatbot",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-12123",
      "affected_versions": [
        "4.8.3",
        "4.8.4",
        "4.8.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-12123",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WOOWBOT-WOOCOMMERCE-CHATBOT-SQLI-CVE-2026-12123",
      "plugin_slug": "woowbot-woocommerce-chatbot",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-12123",
      "affected_versions": [
        "4.8.3",
        "4.8.4",
        "4.8.5"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-12123",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WORDWAVE-XSS-CWE-79",
      "plugin_slug": "wordwave",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WORLD-CUP-PREDICTOR-XSS-CVE-2025-23588",
      "plugin_slug": "world-cup-predictor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-23588",
      "affected_versions": [
        "1.9.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-23588",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WOW-EXTENSIONS-FOR-WOOCOMMERCE-SSRF-CWE-918",
      "plugin_slug": "wow-extensions-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "1.1.0",
        "1.1.1",
        "1.1.2",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOW-EXTENSIONS-FOR-WOOCOMMERCE-SSRF-CWE-918",
      "plugin_slug": "wow-extensions-for-woocommerce",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "1.1.0",
        "1.1.1",
        "1.1.2",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WOW-EXTENSIONS-FOR-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "wow-extensions-for-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1.0",
        "1.1.1",
        "1.1.2",
        "1.2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 34,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-ABSTRACTS-MANUSCRIPTS-MANAGER-XSS-CVE-2024-13654",
      "plugin_slug": "wp-abstracts-manuscripts-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13654",
      "affected_versions": [
        "2.7.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13654",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ACCESSIBILITY-XSS-CWE-79",
      "plugin_slug": "wp-accessibility",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.3",
        "2.3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ADVANCED-PDF-XSS-CVE-2025-62116",
      "plugin_slug": "wp-advanced-pdf",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-62116",
      "affected_versions": [
        "1.1.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-62116",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AIRBNB-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-airbnb-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AIRBNB-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-airbnb-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AIRBNB-REVIEW-SLIDER-XSS-CWE-79",
      "plugin_slug": "wp-airbnb-review-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-CSRF-CVE-2023-5882",
      "plugin_slug": "wp-all-export",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2023-5882",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-5882",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-CSRF-CVE-2023-5886",
      "plugin_slug": "wp-all-export",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2023-5886",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-5886",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-KNOWN-CVE-CVE-2023-4724",
      "plugin_slug": "wp-all-export",
      "vuln_class": "known-cve",
      "severity": "high",
      "cve": "CVE-2023-4724",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2023-4724",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-RCE-CVE-2022-3394",
      "plugin_slug": "wp-all-export",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "high",
      "cve": "CVE-2022-3394",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-3394",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-RCE-CVE-2024-7419",
      "plugin_slug": "wp-all-export",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "high",
      "cve": "CVE-2024-7419",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-7419",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-RCE-CVE-2024-7425",
      "plugin_slug": "wp-all-export",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "cve": "CVE-2024-7425",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-7425",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-EXPORT-SQLI-CVE-2022-3395",
      "plugin_slug": "wp-all-export",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2022-3395",
      "affected_versions": [
        "1.5.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2022-3395",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-IMPORT-DESERIALIZATION-CVE-2026-28073",
      "plugin_slug": "wp-all-import",
      "vuln_class": "deserialization",
      "cwe": "CWE-502",
      "severity": "high",
      "cve": "CVE-2026-28073",
      "affected_versions": [
        "4.1.0",
        "4.1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-28073",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-IMPORT-SQLI-CVE-2026-28073",
      "plugin_slug": "wp-all-import",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-28073",
      "affected_versions": [
        "4.1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-28073",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ALL-IMPORT-SQLI-CVE-2026-28073",
      "plugin_slug": "wp-all-import",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-28073",
      "affected_versions": [
        "4.1.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-28073",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-ASSET-CLEAN-UP-XSS-CVE-2024-9170",
      "plugin_slug": "wp-asset-clean-up",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-9170",
      "affected_versions": [
        "1.4.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-9170",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AUTO-AFFILIATE-LINKS-XSS-CWE-79",
      "plugin_slug": "wp-auto-affiliate-links",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.8.9.3",
        "6.8.9.4",
        "6.8.9.5",
        "6.9",
        "6.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 55,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AUTOKEYWORD-SQLI-CVE-2025-32563",
      "plugin_slug": "wp-autokeyword",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-32563",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AUTOKEYWORD-SQLI-CVE-2025-32563",
      "plugin_slug": "wp-autokeyword",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-32563",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AUTOKEYWORD-XSS-CVE-2025-32563",
      "plugin_slug": "wp-autokeyword",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32563",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 31,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-AWESOME-FAQ-XSS-CWE-79",
      "plugin_slug": "wp-awesome-faq",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-BOOKING-SYSTEM-XSS-CVE-2026-22459",
      "plugin_slug": "wp-booking-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-22459",
      "affected_versions": [
        "2.0.19.14"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-22459",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-BOOKING-SYSTEM-XSS-CVE-2026-22459",
      "plugin_slug": "wp-booking-system",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2026-22459",
      "affected_versions": [
        "2.0.19.14"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-22459",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-BOOKS-GALLERY-XSS-CWE-79",
      "plugin_slug": "wp-books-gallery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-CLICK-TRACK-SQLI-CVE-2025-53563",
      "plugin_slug": "wp-click-track",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-53563",
      "affected_versions": [
        "0.7.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-CLICK-TRACK-SQLI-CVE-2025-53563",
      "plugin_slug": "wp-click-track",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-53563",
      "affected_versions": [
        "0.7.3"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-CLICK-TRACK-XSS-CVE-2025-53563",
      "plugin_slug": "wp-click-track",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53563",
      "affected_versions": [
        "0.7.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 49,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53563",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-CLONE-BY-WP-ACADEMY-XSS-CWE-79",
      "plugin_slug": "wp-clone-by-wp-academy",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.4.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-CONTACT-FORM-7-DB-HANDLER-SQLI-CWE-89",
      "plugin_slug": "wp-contact-form-7-db-handler",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-CONTACT-FORM-7-DB-HANDLER-SQLI-CWE-89",
      "plugin_slug": "wp-contact-form-7-db-handler",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-COPYSAFE-WEB-XSS-CVE-2025-59567",
      "plugin_slug": "wp-copysafe-web",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-59567",
      "affected_versions": [
        "5.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-59567",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-COURSES-XSS-CVE-2026-32491",
      "plugin_slug": "wp-courses",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-32491",
      "affected_versions": [
        "3.2.29"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 28,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-32491",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-DATA-ACCESS-SQLI-CWE-89",
      "plugin_slug": "wp-data-access",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.5.76",
        "5.5.77"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-DATA-ACCESS-SQLI-CWE-89",
      "plugin_slug": "wp-data-access",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.5.76",
        "5.5.77"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 37,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-DATA-ACCESS-XSS-CWE-79",
      "plugin_slug": "wp-data-access",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.5.76",
        "5.5.77"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 39,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-DOCS-XSS-CVE-2024-12195",
      "plugin_slug": "wp-docs",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12195",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12195",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-DONATE-SQLI-CWE-89",
      "plugin_slug": "wp-donate",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-DONATE-SQLI-CWE-89",
      "plugin_slug": "wp-donate",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-DOWNLOADCOUNTER-XSS-CVE-2025-49968",
      "plugin_slug": "wp-downloadcounter",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49968",
      "affected_versions": [
        "1.01"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49968",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-EASY-PAY-XSS-CWE-79",
      "plugin_slug": "wp-easy-pay",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.5.1",
        "4.5.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-EASYCART-SSRF-CVE-2025-12348",
      "plugin_slug": "wp-easycart",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2025-12348",
      "affected_versions": [
        "5.9.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12348",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-EASYCART-SSRF-CVE-2025-12348",
      "plugin_slug": "wp-easycart",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2025-12348",
      "affected_versions": [
        "5.9.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 44,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12348",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-EASYCART-XSS-CVE-2025-12348",
      "plugin_slug": "wp-easycart",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12348",
      "affected_versions": [
        "5.9.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 56,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12348",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-EMAIL-DELIVERY-XSS-CWE-79",
      "plugin_slug": "wp-email-delivery",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.20.11.25"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-EVENT-MANAGER-XSS-CVE-2025-54015",
      "plugin_slug": "wp-event-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-54015",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54015",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-WP-EVENT-MANAGER-XSS-CVE-2025-54015",
      "plugin_slug": "wp-event-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-54015",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 7,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-54015",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-WP-FACEBOOK-REVIEWS-XSS-CVE-2026-32490",
      "plugin_slug": "wp-facebook-reviews",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-32490",
      "affected_versions": [
        "14.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 13,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-32490",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FB-AUTOCONNECT-SQLI-CWE-89",
      "plugin_slug": "wp-fb-autoconnect",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "4.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FB-AUTOCONNECT-SQLI-CWE-89",
      "plugin_slug": "wp-fb-autoconnect",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "4.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FB-AUTOCONNECT-XSS-CWE-79",
      "plugin_slug": "wp-fb-autoconnect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.6.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FOFT-LOADER-XSS-CVE-2025-67979",
      "plugin_slug": "wp-foft-loader",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67979",
      "affected_versions": [
        "2.1.40"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67979",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FORCE-IMAGES-DOWNLOAD-XSS-CWE-79",
      "plugin_slug": "wp-force-images-download",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FRONT-END-PROFILE-XSS-CVE-2026-39485",
      "plugin_slug": "wp-front-end-profile",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39485",
      "affected_versions": [
        "1.3.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39485",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FULLCALENDAR-XSS-CVE-2025-69298",
      "plugin_slug": "wp-fullcalendar",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-69298",
      "affected_versions": [
        "1.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-69298",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-FUSION-LITE-SSRF-CWE-918",
      "plugin_slug": "wp-fusion-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.47.13",
        "3.47.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 40,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-FUSION-LITE-SSRF-CWE-918",
      "plugin_slug": "wp-fusion-lite",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.47.13",
        "3.47.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-FUSION-LITE-XSS-CWE-79",
      "plugin_slug": "wp-fusion-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.47.13",
        "3.47.14"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GEONAMES-SQLI-CVE-2024-11884",
      "plugin_slug": "wp-geonames",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-11884",
      "affected_versions": [
        "1.9.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-GEONAMES-SQLI-CVE-2024-11884",
      "plugin_slug": "wp-geonames",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-11884",
      "affected_versions": [
        "1.9.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-GEONAMES-XSS-CVE-2024-11884",
      "plugin_slug": "wp-geonames",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11884",
      "affected_versions": [
        "1.9.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11884",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-ANALYTICS-EVENTS-XSS-CWE-79",
      "plugin_slug": "wp-google-analytics-events",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-MY-BUSINESS-AUTO-PUBLISH-SSRF-CWE-918",
      "plugin_slug": "wp-google-my-business-auto-publish",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "3.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-MY-BUSINESS-AUTO-PUBLISH-SSRF-CWE-918",
      "plugin_slug": "wp-google-my-business-auto-publish",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "3.13"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-RCE-CWE-94",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-RCE-CWE-95",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-SSRF-CWE-918",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 17,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-SSRF-CWE-918",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GOOGLE-PLACES-REVIEW-SLIDER-XSS-CWE-79",
      "plugin_slug": "wp-google-places-review-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "18.2",
        "18.3",
        "18.4",
        "18.5",
        "18.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 132,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-GROUP-SUBSCRIPTIONS-SQLI-CWE-89",
      "plugin_slug": "wp-group-subscriptions",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "0.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GROUP-SUBSCRIPTIONS-SQLI-CWE-89",
      "plugin_slug": "wp-group-subscriptions",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "0.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-GROUP-SUBSCRIPTIONS-XSS-CWE-79",
      "plugin_slug": "wp-group-subscriptions",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.1.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-HEADMASTER-XSS-CVE-2025-23506",
      "plugin_slug": "wp-headmaster",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-23506",
      "affected_versions": [
        "0.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-23506",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-HEALTH-XSS-CVE-2024-53810",
      "plugin_slug": "wp-health",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-53810",
      "affected_versions": [
        "2.25.0",
        "2.25.1",
        "2.26.0",
        "2.26.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-53810",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-HELPER-LITE-XSS-CWE-79",
      "plugin_slug": "wp-helper-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.7.2",
        "4.7.3",
        "4.7.4",
        "4.7.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 138,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-IMPORT-EXPORT-LITE-SQLI-CWE-89",
      "plugin_slug": "wp-import-export-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.9.32"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-IMPORT-EXPORT-LITE-SQLI-CWE-89",
      "plugin_slug": "wp-import-export-lite",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.9.32"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-KEYBASE-VERIFICATION-XSS-CVE-2025-12172",
      "plugin_slug": "wp-keybase-verification",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12172",
      "affected_versions": [
        "1.4.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12172",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LIMIT-FAILED-LOGIN-ATTEMPTS-SQLI-CWE-89",
      "plugin_slug": "wp-limit-failed-login-attempts",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "5.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LIMIT-FAILED-LOGIN-ATTEMPTS-SQLI-CWE-89",
      "plugin_slug": "wp-limit-failed-login-attempts",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "5.6"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LISTER-FOR-AMAZON-XSS-CWE-79",
      "plugin_slug": "wp-lister-for-amazon",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.9.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 29,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-LISTER-FOR-EBAY-RCE-CWE-94",
      "plugin_slug": "wp-lister-for-ebay",
      "vuln_class": "rce",
      "cwe": "CWE-94",
      "severity": "medium",
      "affected_versions": [
        "3.8.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "warn",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LISTER-FOR-EBAY-RCE-CWE-95",
      "plugin_slug": "wp-lister-for-ebay",
      "vuln_class": "rce",
      "cwe": "CWE-95",
      "severity": "critical",
      "affected_versions": [
        "3.8.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LISTER-FOR-EBAY-XSS-CWE-79",
      "plugin_slug": "wp-lister-for-ebay",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-LUCKY-WHEEL-XSS-CVE-2026-39647",
      "plugin_slug": "wp-lucky-wheel",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-39647",
      "affected_versions": [
        "1.1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39647",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-MAIL-XSS-CVE-2025-68849",
      "plugin_slug": "wp-mail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-68849",
      "affected_versions": [
        "1.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-68849",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-MAILSTER-XSS-CVE-2024-12408",
      "plugin_slug": "wp-mailster",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12408",
      "affected_versions": [
        "1.8.23.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 46,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12408",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-MEDIA-CATEGORIES-XSS-CWE-79",
      "plugin_slug": "wp-media-categories",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.1.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-META-AND-DATE-REMOVER-XSS-CWE-79",
      "plugin_slug": "wp-meta-and-date-remover",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.3.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-META-DATA-FILTER-AND-TAXONOMY-FILTER-SQLI-CVE-2025-60081",
      "plugin_slug": "wp-meta-data-filter-and-taxonomy-filter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-60081",
      "affected_versions": [
        "1.3.9"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60081",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-META-DATA-FILTER-AND-TAXONOMY-FILTER-SQLI-CVE-2025-60081",
      "plugin_slug": "wp-meta-data-filter-and-taxonomy-filter",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-60081",
      "affected_versions": [
        "1.3.9"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-60081",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-MIGRATION-DUPLICATOR-XSS-CWE-79",
      "plugin_slug": "wp-migration-duplicator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-NICE-LOADER-XSS-CVE-2025-24583",
      "plugin_slug": "wp-nice-loader",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24583",
      "affected_versions": [
        "0.1.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24583",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-NOTIFICATION-BELL-XSS-CVE-2025-58826",
      "plugin_slug": "wp-notification-bell",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58826",
      "affected_versions": [
        "1.4.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58826",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-PAGE-EXTENSION-SQLI-CWE-89",
      "plugin_slug": "wp-page-extension",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-PAGE-EXTENSION-SQLI-CWE-89",
      "plugin_slug": "wp-page-extension",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-PLUGIN-MANAGER-XSS-CVE-2025-12526",
      "plugin_slug": "wp-plugin-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-12526",
      "affected_versions": [
        "1.4.13",
        "1.4.14"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12526",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-POLLS-SQLI-CWE-89",
      "plugin_slug": "wp-polls",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.77.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-POLLS-XSS-CWE-79",
      "plugin_slug": "wp-polls",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.77.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-POST-AUTHOR-XSS-CWE-79",
      "plugin_slug": "wp-post-author",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.10.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 11,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-POST-CORRECTOR-XSS-CVE-2024-13115",
      "plugin_slug": "wp-post-corrector",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13115",
      "affected_versions": [
        "1.0.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13115",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-RELATED-ITEMS-XSS-CWE-79",
      "plugin_slug": "wp-related-items",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-PHOTO-GALLERY-SQLI-CVE-2024-56225",
      "plugin_slug": "wp-responsive-photo-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-56225",
      "affected_versions": [
        "1.0.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 30,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56225",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-PHOTO-GALLERY-SQLI-CVE-2024-56225",
      "plugin_slug": "wp-responsive-photo-gallery",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-56225",
      "affected_versions": [
        "1.0.17"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56225",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-PHOTO-GALLERY-SSRF-CVE-2024-56225",
      "plugin_slug": "wp-responsive-photo-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "cve": "CVE-2024-56225",
      "affected_versions": [
        "1.0.17"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56225",
      "first_seen": "2026-07-20"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-PHOTO-GALLERY-SSRF-CVE-2024-56225",
      "plugin_slug": "wp-responsive-photo-gallery",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "cve": "CVE-2024-56225",
      "affected_versions": [
        "1.0.17"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56225",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-THUMBNAIL-SLIDER-SQLI-CVE-2025-2250",
      "plugin_slug": "wp-responsive-thumbnail-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-2250",
      "affected_versions": [
        "1.1.14"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 11,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2250",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-THUMBNAIL-SLIDER-SQLI-CVE-2025-2250",
      "plugin_slug": "wp-responsive-thumbnail-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-2250",
      "affected_versions": [
        "1.1.14"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2250",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-RESPONSIVE-THUMBNAIL-SLIDER-XSS-CVE-2025-2250",
      "plugin_slug": "wp-responsive-thumbnail-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-2250",
      "affected_versions": [
        "1.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-2250",
      "first_seen": "2026-07-25"
    },
    {
      "id": "CLR-WP-WP-RSS-AGGREGATOR-XSS-CWE-79",
      "plugin_slug": "wp-rss-aggregator",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.2.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-SCHOOL-CALENDAR-LITE-XSS-CWE-79",
      "plugin_slug": "wp-school-calendar-lite",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.8.23",
        "3.8.24"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 49,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-SECURITY-AUDIT-LOG-XSS-CVE-2026-8442",
      "plugin_slug": "wp-security-audit-log",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-8442",
      "affected_versions": [
        "5.6.4",
        "5.6.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 41,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-8442",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-SHOW-STATS-SQLI-CVE-2025-30966",
      "plugin_slug": "wp-show-stats",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-30966",
      "affected_versions": [
        "1.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30966",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-SHOW-STATS-SQLI-CVE-2025-30966",
      "plugin_slug": "wp-show-stats",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-30966",
      "affected_versions": [
        "1.5"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-30966",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-SIMPLE-REDIRECT-XSS-CVE-2026-22329",
      "plugin_slug": "wp-simple-redirect",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-22329",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-22329",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-SMART-FLEXSLIDER-XSS-CVE-2025-48170",
      "plugin_slug": "wp-smart-flexslider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-48170",
      "affected_versions": [
        "2.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 27,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-48170",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-SOCIAL-WIDGET-XSS-CVE-2025-5568",
      "plugin_slug": "wp-social-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-5568",
      "affected_versions": [
        "2.3.1"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-5568",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-STAGING-CSRF-CWE-352",
      "plugin_slug": "wp-staging",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "affected_versions": [
        "4.9.2",
        "4.9.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-STAGING-CSRF-CVE-2024-5551",
      "plugin_slug": "wp-staging",
      "vuln_class": "csrf",
      "cwe": "CWE-352",
      "severity": "high",
      "cve": "CVE-2024-5551",
      "affected_versions": [
        "4.9.2",
        "4.9.3",
        "4.9.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-5551",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-STATS-MANAGER-XSS-CVE-2025-49991",
      "plugin_slug": "wp-stats-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-49991",
      "affected_versions": [
        "8.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-49991",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-STRIPE-EXPRESS-XSS-CWE-79",
      "plugin_slug": "wp-stripe-express",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.28.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TAB-WIDGET-XSS-CWE-79",
      "plugin_slug": "wp-tab-widget",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.11"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-TABLE-EDITOR-SQLI-CVE-2024-13561",
      "plugin_slug": "wp-table-editor",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-13561",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13561",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TABLE-EDITOR-SQLI-CVE-2024-13561",
      "plugin_slug": "wp-table-editor",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-13561",
      "affected_versions": [
        "1.6.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 15,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13561",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TACTICAL-POPUP-SQLI-CVE-2025-53423",
      "plugin_slug": "wp-tactical-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-53423",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 4,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53423",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TACTICAL-POPUP-SQLI-CVE-2025-53423",
      "plugin_slug": "wp-tactical-popup",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-53423",
      "affected_versions": [
        "1.1"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53423",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TEAM-MANAGER-XSS-CVE-2025-58247",
      "plugin_slug": "wp-team-manager",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58247",
      "affected_versions": [
        "2.5.3",
        "2.6.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 25,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58247",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-TEST-EMAIL-XSS-CVE-2025-67614",
      "plugin_slug": "wp-test-email",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-67614",
      "affected_versions": [
        "1.1.7"
      ],
      "source": "cve",
      "engines": [
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67614",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-TEST-EMAIL-XSS-CVE-2025-67614",
      "plugin_slug": "wp-test-email",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-67614",
      "affected_versions": [
        "1.1.7"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-67614",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-THUMBTACK-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-thumbtack-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-THUMBTACK-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-thumbtack-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-THUMBTACK-REVIEW-SLIDER-XSS-CWE-79",
      "plugin_slug": "wp-thumbtack-review-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TIME-SLOTS-BOOKING-FORM-SQLI-CVE-2026-39499",
      "plugin_slug": "wp-time-slots-booking-form",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-39499",
      "affected_versions": [
        "1.2.52",
        "1.2.53"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39499",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-TIME-SLOTS-BOOKING-FORM-SQLI-CVE-2026-39499",
      "plugin_slug": "wp-time-slots-booking-form",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-39499",
      "affected_versions": [
        "1.2.52",
        "1.2.53"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-39499",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-TOOL-XSS-CWE-79",
      "plugin_slug": "wp-tool",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-TRIPADVISOR-REVIEW-SLIDER-XSS-CWE-79",
      "plugin_slug": "wp-tripadvisor-review-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "14.4",
        "14.6",
        "14.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 70,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-TWILIO-CORE-XSS-CWE-79",
      "plugin_slug": "wp-twilio-core",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-USER-STYLESHEET-SWITCHER-XSS-CVE-2025-5490",
      "plugin_slug": "wp-user-stylesheet-switcher",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-5490",
      "affected_versions": [
        "v2.2.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-5490",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-VOTING-XSS-CVE-2025-55713",
      "plugin_slug": "wp-voting",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-55713",
      "affected_versions": [
        "1.8"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-55713",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-W3ALL-PHPBB-INTEGRATION-SQLI-CVE-2025-32630",
      "plugin_slug": "wp-w3all-phpbb-integration",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-32630",
      "affected_versions": [
        "3.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32630",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-W3ALL-PHPBB-INTEGRATION-SQLI-CVE-2025-32630",
      "plugin_slug": "wp-w3all-phpbb-integration",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-32630",
      "affected_versions": [
        "3.0.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32630",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-W3ALL-PHPBB-INTEGRATION-XSS-CVE-2025-32630",
      "plugin_slug": "wp-w3all-phpbb-integration",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32630",
      "affected_versions": [
        "3.0.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 46,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32630",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-WEBINARSYSTEM-XSS-CVE-2025-32117",
      "plugin_slug": "wp-webinarsystem",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32117",
      "affected_versions": [
        "1.33.29"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32117",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-YELP-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-yelp-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "8.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-YELP-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-yelp-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "8.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-YELP-REVIEW-SLIDER-XSS-CWE-79",
      "plugin_slug": "wp-yelp-review-slider",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.5"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP-YOUTUBE-LYTE-XSS-CVE-2025-12019",
      "plugin_slug": "wp-youtube-lyte",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-12019",
      "affected_versions": [
        "1.7.30"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-12019",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WP-ZILLOW-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-zillow-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP-ZILLOW-REVIEW-SLIDER-SQLI-CWE-89",
      "plugin_slug": "wp-zillow-review-slider",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WP24-DOMAIN-CHECK-XSS-CVE-2025-24565",
      "plugin_slug": "wp24-domain-check",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24565",
      "affected_versions": [
        "1.12.0"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24565",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP2LEADS-SQLI-CWE-89",
      "plugin_slug": "wp2leads",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP2LEADS-SQLI-CWE-89",
      "plugin_slug": "wp2leads",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WP2LEADS-XSS-CWE-79",
      "plugin_slug": "wp2leads",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.5.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 71,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPAPPNINJA-XSS-CWE-79",
      "plugin_slug": "wpappninja",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "11.78",
        "11.79"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 76,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WPBENCHMARK-XSS-CWE-79",
      "plugin_slug": "wpbenchmark",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.6.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-30"
    },
    {
      "id": "CLR-WP-WPBITS-ADDONS-FOR-ELEMENTOR-XSS-CVE-2024-56241",
      "plugin_slug": "wpbits-addons-for-elementor",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-56241",
      "affected_versions": [
        "1.8.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-56241",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPBOOKIT-FILE-UPLOAD-CVE-2024-55980",
      "plugin_slug": "wpbookit",
      "vuln_class": "file-upload",
      "cwe": "CWE-434",
      "severity": "critical",
      "cve": "CVE-2024-55980",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-55980",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPBOOKIT-KNOWN-CVE-CVE-2024-55980",
      "plugin_slug": "wpbookit",
      "vuln_class": "known-cve",
      "cwe": "CWE-639",
      "severity": "critical",
      "cve": "CVE-2024-55980",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-55980",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPBOOKIT-SQLI-CVE-2024-55980",
      "plugin_slug": "wpbookit",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-55980",
      "affected_versions": [
        "1.0.9"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-55980",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPCASA-XSS-CVE-2024-11325",
      "plugin_slug": "wpcasa",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-11325",
      "affected_versions": [
        "1.5.2",
        "1.5.3"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-11325",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPCOMPLETE-XSS-CVE-2026-7660",
      "plugin_slug": "wpcomplete",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-7660",
      "affected_versions": [
        "2.9.5.6"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 12,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-7660",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPEMATICO-XSS-CWE-79",
      "plugin_slug": "wpematico",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.8.22"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPFORO-SQLI-CVE-2026-3875",
      "plugin_slug": "wpforo",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2026-3875",
      "affected_versions": [
        "3.1.1",
        "3.1.2",
        "3.1.3",
        "3.1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 8,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3875",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPFORO-SQLI-CVE-2026-3875",
      "plugin_slug": "wpforo",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2026-3875",
      "affected_versions": [
        "3.1.1",
        "3.1.2",
        "3.1.3",
        "3.1.4"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 92,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3875",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPFORO-XSS-CVE-2026-3875",
      "plugin_slug": "wpforo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2026-3875",
      "affected_versions": [
        "3.1.1",
        "3.1.2",
        "3.1.3",
        "3.1.4"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 247,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2026-3875",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPFUNNELS-XSS-CVE-2025-6692",
      "plugin_slug": "wpfunnels",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-6692",
      "affected_versions": [
        "2.0.4",
        "3.12.10"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "nvd-known",
        "semgrep"
      ],
      "evidence_count": 102,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6692",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-WPFUNNELS-XSS-CVE-2025-6692",
      "plugin_slug": "wpfunnels",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-6692",
      "affected_versions": [
        "2.0.4"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-6692",
      "first_seen": "2026-07-21"
    },
    {
      "id": "CLR-WP-WPIDE-XSS-CWE-79",
      "plugin_slug": "wpide",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.5.6",
        "3.5.7",
        "3.5.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 44,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WPIFY-WOO-XSS-CWE-79",
      "plugin_slug": "wpify-woo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "5.4.15",
        "5.4.16",
        "5.4.17",
        "5.4.18"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 23,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPLR-SYNC-XSS-CWE-79",
      "plugin_slug": "wplr-sync",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.5.3",
        "6.5.4"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 24,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPMKTGENGINE-XSS-CWE-79",
      "plugin_slug": "wpmktgengine",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.37"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-13"
    },
    {
      "id": "CLR-WP-WPNAMEDUSERS-SQLI-CVE-2025-58972",
      "plugin_slug": "wpnamedusers",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2025-58972",
      "affected_versions": [
        "0.5"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58972",
      "first_seen": "2026-07-11"
    },
    {
      "id": "CLR-WP-WPNAMEDUSERS-SQLI-CVE-2025-58972",
      "plugin_slug": "wpnamedusers",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2025-58972",
      "affected_versions": [
        "0.5"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58972",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPOS-LITE-VERSION-XSS-CWE-79",
      "plugin_slug": "wpos-lite-version",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 42,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPPIZZA-XSS-CWE-79",
      "plugin_slug": "wppizza",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.20.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 67,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPS-TEAM-XSS-CWE-79",
      "plugin_slug": "wps-team",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.1.0",
        "4.1.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 18,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPSCHOOLPRESS-SQLI-CVE-2024-12067",
      "plugin_slug": "wpschoolpress",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "critical",
      "cve": "CVE-2024-12067",
      "affected_versions": [
        "2.2.45",
        "2.2.46"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 2,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12067",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPSCHOOLPRESS-SQLI-CVE-2024-12067",
      "plugin_slug": "wpschoolpress",
      "vuln_class": "sqli",
      "cwe": "CWE-89",
      "severity": "high",
      "cve": "CVE-2024-12067",
      "affected_versions": [
        "2.2.45",
        "2.2.46"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12067",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPSCHOOLPRESS-XSS-CVE-2024-12067",
      "plugin_slug": "wpschoolpress",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-12067",
      "affected_versions": [
        "2.2.45",
        "2.2.46"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 73,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-12067",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPSSO-XSS-CWE-79",
      "plugin_slug": "wpsso",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "22.4.0",
        "22.5.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-WPSTREAM-XSS-CWE-79",
      "plugin_slug": "wpstream",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.13",
        "4.13.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 54,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-WPTOOLS-MASONRY-GALLERY-POSTS-FOR-DIVI-XSS-CWE-79",
      "plugin_slug": "wptools-masonry-gallery-posts-for-divi",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WPVIVID-BACKUPRESTORE-XSS-CVE-2025-24606",
      "plugin_slug": "wpvivid-backuprestore",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-24606",
      "affected_versions": [
        "0.9.130",
        "0.9.131",
        "0.9.132"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 173,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-24606",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WRITERS-PRO-XSS-CWE-79",
      "plugin_slug": "writers-pro",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-WSANALYTICS-GOOGLE-ANALYTICS-AND-DASHBOARDS-XSS-CVE-2025-11380",
      "plugin_slug": "wsanalytics-google-analytics-and-dashboards",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-11380",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 16,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-11380",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-XAGIO-SEO-SSRF-CWE-918",
      "plugin_slug": "xagio-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "7.1.0.41",
        "7.1.0.42"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 10,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-XAGIO-SEO-SSRF-CWE-918",
      "plugin_slug": "xagio-seo",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "7.1.0.41",
        "7.1.0.42"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 22,
      "action": "warn",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-XAGIO-SEO-XSS-CWE-79",
      "plugin_slug": "xagio-seo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.1.0.41",
        "7.1.0.42"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 14,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-XILI-DICTIONARY-XSS-CVE-2025-53200",
      "plugin_slug": "xili-dictionary",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-53200",
      "affected_versions": [
        "2.12.5.2"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-53200",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-XILI-LANGUAGE-XSS-CWE-79",
      "plugin_slug": "xili-language",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.21.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 49,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-XM-BACKUP-XSS-CVE-2025-58198",
      "plugin_slug": "xm-backup",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-58198",
      "affected_versions": [
        "0.9.1"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-58198",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-XO-FEATURED-IMAGE-TOOLS-XSS-CWE-79",
      "plugin_slug": "xo-featured-image-tools",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.15.3"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-YAY-CUSTOMER-REVIEWS-WOOCOMMERCE-XSS-CWE-79",
      "plugin_slug": "yay-customer-reviews-woocommerce",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.3.0",
        "1.3.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 6,
      "action": "block",
      "first_seen": "2026-07-17"
    },
    {
      "id": "CLR-WP-YAYMAIL-XSS-CWE-79",
      "plugin_slug": "yaymail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.4.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 2,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-YEEMAIL-XSS-CWE-79",
      "plugin_slug": "yeemail",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-YELLOW-PENCIL-VISUAL-THEME-CUSTOMIZER-XSS-CWE-79",
      "plugin_slug": "yellow-pencil-visual-theme-customizer",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "7.6.7"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-YITH-WOOCOMMERCE-PRODUCT-ADD-ONS-XSS-CWE-79",
      "plugin_slug": "yith-woocommerce-product-add-ons",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "4.31.0",
        "4.32.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-YITH-WOOCOMMERCE-REQUEST-A-QUOTE-XSS-CWE-79",
      "plugin_slug": "yith-woocommerce-request-a-quote",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "2.51.0"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 9,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-YMM-SEARCH-XSS-CWE-79",
      "plugin_slug": "ymm-search",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.0.12"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 7,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-YOURCHANNEL-XSS-CWE-79",
      "plugin_slug": "yourchannel",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "1.2.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 3,
      "action": "block",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-YOUZIFY-XSS-CVE-2024-13551",
      "plugin_slug": "youzify",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2024-13551",
      "affected_versions": [
        "1.3.7"
      ],
      "source": "cve",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 26,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2024-13551",
      "first_seen": "2026-07-09"
    },
    {
      "id": "CLR-WP-Z-COMPANION-XSS-CVE-2025-32114",
      "plugin_slug": "z-companion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "cve": "CVE-2025-32114",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 1,
      "action": "block",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32114",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-Z-COMPANION-XSS-CVE-2025-32114",
      "plugin_slug": "z-companion",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "medium",
      "cve": "CVE-2025-32114",
      "affected_versions": [
        "1.1.2"
      ],
      "source": "cve",
      "engines": [
        "nvd-known"
      ],
      "evidence_count": 1,
      "action": "warn",
      "reference": "https://nvd.nist.gov/vuln/detail/CVE-2025-32114",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ZEJ-FORMS-XSS-CWE-79",
      "plugin_slug": "zej-forms",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "0.5.9"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 5,
      "action": "block",
      "first_seen": "2026-07-26"
    },
    {
      "id": "CLR-WP-ZERO-BS-CRM-SSRF-CWE-918",
      "plugin_slug": "zero-bs-crm",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "high",
      "affected_versions": [
        "6.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint"
      ],
      "evidence_count": 1,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ZERO-BS-CRM-SSRF-CWE-918",
      "plugin_slug": "zero-bs-crm",
      "vuln_class": "ssrf",
      "cwe": "CWE-918",
      "severity": "medium",
      "affected_versions": [
        "6.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "semgrep"
      ],
      "evidence_count": 8,
      "action": "warn",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ZERO-BS-CRM-XSS-CWE-79",
      "plugin_slug": "zero-bs-crm",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "6.8.1"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 20,
      "action": "block",
      "first_seen": "2026-07-08"
    },
    {
      "id": "CLR-WP-ZIGGEO-XSS-CWE-79",
      "plugin_slug": "ziggeo",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "3.1.2"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 4,
      "action": "block",
      "first_seen": "2026-07-10"
    },
    {
      "id": "CLR-WP-ZIP-RECIPES-XSS-CWE-79",
      "plugin_slug": "zip-recipes",
      "vuln_class": "xss",
      "cwe": "CWE-79",
      "severity": "high",
      "affected_versions": [
        "8.2.8"
      ],
      "source": "codelake-sast",
      "engines": [
        "mosaic-taint",
        "semgrep"
      ],
      "evidence_count": 19,
      "action": "block",
      "first_seen": "2026-07-10"
    }
  ]
}