← All credits
WPScan
3994 vulnerability records and advisories credit this contributor.
CVE-2026-18779
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked
CVE-2026-18778
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions
CVE-2026-18777
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status
CVE-2026-18776
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions
CVE-2026-18666
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
CVE-2026-18653
WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
CVE-2026-18474
WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category
CVE-2026-18466
WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation
CVE-2026-18391
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator