← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2026-92995
Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file
CVE-2026-92436
Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
CVE-2026-92411
WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name
CVE-2026-89411
Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
CVE-2026-89303
Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
CVE-2026-89300
WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
CVE-2026-89237
Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters
CVE-2026-89006
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
CVE-2026-89003
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
CVE-2026-89001
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings