← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-12500
WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVE-2026-11870
Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
CVE-2026-14318
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVE-2026-14231
LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
CVE-2026-13145
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVE-2026-13143
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVE-2026-11867
Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
CVE-2026-11782
Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR
CVE-2026-15382
Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts
CVE-2026-15257
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification