← All credits
M Indra Purnama
39 vulnerability records and advisories credit this contributor.
CVE-2025-13737
Nextend Social Login and Register <= 3.1.21 - Cross-Site Request Forgery to Unlink User Social Login
CVE-2025-12894
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure
CVE-2025-12849
Contest Gallery <= 28.0.2 - Missing Authorization
CVE-2025-12620
Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter
CVE-2025-12536
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
CVE-2025-14056
Custom Post Type UI <= 1.18.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter
CVE-2025-12900
FileBird – WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering
CVE-2025-12496
Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery
CVE-2025-12851
My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller
CVE-2026-3139
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field