← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2026-97219
MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
CVE-2026-92924
Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data
CVE-2026-91020
WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount
CVE-2026-90987
Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
CVE-2026-90952
WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API
CVE-2026-85005
Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
CVE-2026-84740
The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter
CVE-2026-79618
WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
CVE-2026-1661
WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
CVE-2026-13413
CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match