← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2026-84096
WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields
CVE-2026-84095
WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import
CVE-2026-84069
WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php
CVE-2026-82841
UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice
CVE-2026-81655
Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields
CVE-2026-19708
File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure
CVE-2026-97319
PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
CVE-2026-97227
NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
CVE-2026-96899
Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
CVE-2026-96897
Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache