← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-14332
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
CVE-2026-14325
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting
CVE-2026-14290
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
CVE-2026-14287
TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
CVE-2026-14230
ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
CVE-2026-14229
ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
CVE-2026-14216
Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch
CVE-2026-14213
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
CVE-2026-14212
Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR
CVE-2026-14196
WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR