← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-14187
Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOR
CVE-2026-14182
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
CVE-2026-13736
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
CVE-2026-13712
Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
CVE-2026-13700
WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure
CVE-2026-13613
KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint
CVE-2026-13612
KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR
CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
CVE-2026-13406
Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure
CVE-2026-13405
Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder