← All credits
Ryan Fabella
11 vulnerability records and advisories credit this contributor.
CVE-2026-103692
Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Function Call
CVE-2026-87782
Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
CVE-2026-104678
CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
CVE-2026-104651
Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR
CVE-2026-93580
InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
CVE-2026-87981
Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions
CVE-2026-78474
Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter
CVE-2026-82213
Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
CVE-2026-18469
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force