← All credits
Lucio Sá
338 vulnerability records and advisories credit this contributor.
CVE-2026-15302
ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
CVE-2025-2289
Zegen - Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates
CVE-2025-1285
Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update
CVE-2025-1284
Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) <= 4.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure
CVE-2025-0959
Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id
CVE-2025-0956
WooCommerce Recover Abandoned Cart <= 24.4.0 - Unauthenticated PHP Object Injection
CVE-2025-0955
VidoRev Extensions <= 2.9.9.9.9.9.5 - Missing Authorization to Unauthenticated Youtube Video Import
CVE-2025-0954
WP Online Contract <= 5.1.4 - Missing Authorization to Unauthenticated Settings Import
CVE-2025-0952
Eco Nature - Environment & Ecology WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
CVE-2025-0951
LiquidThemes Themes <= Various Versions - Missing Authorization to Authenticated (Subscriber+) All Plugins Deactivated