← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-15047
s2Member < 260805 - Contributor+ Stored XSS via Shortcode
CVE-2026-15038
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
CVE-2026-15032
wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
CVE-2026-14943
Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
CVE-2026-14939
Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
CVE-2026-14936
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
CVE-2026-14872
Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter
CVE-2026-14860
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
CVE-2026-14848
Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout