← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-14205
WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
CVE-2026-14204
Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
CVE-2026-13703
SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
CVE-2026-13701
Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
CVE-2026-13600
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
CVE-2026-13399
Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
CVE-2026-13170
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE-2026-13154
Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
CVE-2026-13153
Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint