← All credits
WPScan
3994 vulnerability records and advisories credit this contributor.
CVE-2026-16737
WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
CVE-2026-16650
Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass
CVE-2026-16621
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
CVE-2026-16617
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
CVE-2026-16616
Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
CVE-2026-16612
FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
CVE-2026-16577
Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount
CVE-2026-16576
Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
CVE-2026-16575
Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint