← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
CVE-2026-12901
GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
CVE-2026-12713
WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
CVE-2026-12698
wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
CVE-2026-12584
Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
CVE-2026-12501
WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
CVE-2026-11976
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
CVE-2026-11588
EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation
CVE-2026-11366
MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
CVE-2026-11361
Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status