← All credits
WPScan
3974 vulnerability records and advisories credit this contributor.
CVE-2026-16070
Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
CVE-2026-16069
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
CVE-2026-16068
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
CVE-2026-16065
Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
CVE-2026-16056
Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
CVE-2026-16054
Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
CVE-2026-16041
MStore API < 4.21.0 - Unauthenticated Product Review Creation
CVE-2026-16039
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR