← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-16977
Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
CVE-2026-16962
Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
CVE-2026-16950
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
CVE-2026-16747
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
CVE-2026-16738
Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Forgery
CVE-2026-16737
WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
CVE-2026-16650
Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass
CVE-2026-16621
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
CVE-2026-16617
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description