← All credits
WPScan
3994 vulnerability records and advisories credit this contributor.
CVE-2026-18356
Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email
CVE-2026-18231
WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
CVE-2026-18230
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
CVE-2026-18202
JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload
CVE-2026-18057
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection
CVE-2026-18052
ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login Parameters
CVE-2026-18051
W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key
CVE-2026-18049
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo
CVE-2026-18048
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal