← All credits
WPScan
3994 vulnerability records and advisories credit this contributor.
CVE-2026-18046
Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update
CVE-2026-18044
Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
CVE-2026-18035
User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
CVE-2026-18031
TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback
CVE-2026-17565
Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
CVE-2026-17559
Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass
CVE-2026-17533
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
CVE-2026-17013
WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart
CVE-2026-17008
Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN