← All credits
WPScan
3994 vulnerability records and advisories credit this contributor.
CVE-2026-16990
Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
CVE-2026-16986
Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters
CVE-2026-16984
WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure
CVE-2026-16979
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
CVE-2026-16977
Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
CVE-2026-16962
Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
CVE-2026-16950
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
CVE-2026-16747
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
CVE-2026-16738
Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Forgery