← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-14857
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR
CVE-2026-14853
WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization
CVE-2026-14832
ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone
CVE-2026-14826
Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR
CVE-2026-14825
Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR
CVE-2026-14601
Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter
CVE-2026-14550
WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization
CVE-2026-14549
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion
CVE-2026-14548
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update
CVE-2026-14334
Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload