← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-15205
Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup
CVE-2026-15150
myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED
CVE-2026-15049
Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
CVE-2026-15046
LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRF
CVE-2026-15045
Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount
CVE-2026-15039
Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
CVE-2026-14925
Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download
CVE-2026-14861
User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR
CVE-2026-14859
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization
CVE-2026-14858
WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR