← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2026-89000
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
CVE-2026-88828
Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords
CVE-2026-86841
Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options
CVE-2026-86839
Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR
CVE-2026-86838
Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation
CVE-2026-86609
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
CVE-2026-85081
Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass
CVE-2026-85002
EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes
CVE-2026-84744
WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
CVE-2026-84097
WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter