← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-16039
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
CVE-2026-16036
miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
CVE-2026-16035
miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
CVE-2026-16032
LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
CVE-2026-15958
Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
CVE-2026-15386
Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
CVE-2026-15372
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
CVE-2026-15361
Content Views < 4.5 - Subscriber+ SQL Injection via preview_request