← All credits
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
249 vulnerability records and advisories credit this contributor.
CVE-2026-62073
WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
CVE-2026-103068
WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability
CVE-2026-97284
WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability
CVE-2026-97260
WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-97258
WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
CVE-2026-94390
WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability
CVE-2026-97291
WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vulnerability
CVE-2026-97256
WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability
CVE-2026-102392
WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin <= 3.3.8 - PHP Object Injection vulnerability
CVE-2026-102377
WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability