← All credits
WPScan
3978 vulnerability records and advisories credit this contributor.
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
CVE-2026-10526
EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
CVE-2026-10524
CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
CVE-2026-78146
Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page
CVE-2026-77789
Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR
CVE-2026-77758
Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session
CVE-2026-77757
Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission
CVE-2026-77754
Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis
CVE-2026-77695
Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation
CVE-2026-77694
Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token