← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-11974
Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download
CVE-2026-14226
Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
CVE-2026-14239
Tourmaster < 5.4.8 - Stored XSS via CSRF
CVE-2026-14602
Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter
CVE-2026-15235
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
CVE-2026-15153
WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVE-2026-15054
Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission
CVE-2026-13395
Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
CVE-2026-13345
Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
CVE-2026-13178
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation