← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-14207
LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information
CVE-2026-12687
ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
CVE-2026-13690
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
CVE-2026-13605
Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
CVE-2026-13423
Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
CVE-2026-13344
Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
CVE-2026-13330
Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
CVE-2026-11881
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
CVE-2026-11351
ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure
CVE-2024-3823
Base64 Encoder/Decoder <= 0.9.2 - Stored XSS via CSRF