← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-15360
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
CVE-2026-15359
Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
CVE-2026-15246
RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
CVE-2026-15239
Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
CVE-2026-15238
Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
CVE-2026-15237
Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
CVE-2026-15233
Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
CVE-2026-15230
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure