← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2024-3824
Base64 Encoder/Decoder <= 0.9.2 - Settings Reset via CSRF
CVE-2024-3822
Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS
CVE-2026-14926
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
CVE-2026-14924
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
CVE-2026-14870
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVE-2026-14819
Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVE-2026-14545
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
CVE-2026-9830
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
CVE-2026-14827
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter