← All credits
Marco Wotschka
232 vulnerability records and advisories credit this contributor.
CVE-2025-8561
Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE-2025-6423
BeeTeam368 Extensions <= 2.3.5 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-8123
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Insecure Direct Object Reference
CVE-2024-8121
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change
CVE-2024-8119
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page
CVE-2024-8117
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option
CVE-2024-8106
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure
CVE-2024-8104
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download
CVE-2024-8102
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update
CVE-2024-7894
If Menu <= 0.19.1 - Missing Authorization to License Key Update