← All credits
WPScan
3974 vulnerability records and advisories credit this contributor.
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
CVE-2026-16036
miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
CVE-2026-16035
miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
CVE-2026-16032
LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
CVE-2026-15958
Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
CVE-2026-15386
Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
CVE-2026-15372
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
CVE-2026-15361
Content Views < 4.5 - Subscriber+ SQL Injection via preview_request
CVE-2026-15360
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args