← All credits
WPScan
4010 vulnerability records and advisories credit this contributor.
CVE-2026-14820
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
CVE-2026-14568
WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
CVE-2026-14289
WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
CVE-2026-14236
Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
CVE-2026-14235
WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
CVE-2026-14203
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
CVE-2026-14190
Sina Extension for Elementor < 3.10.2 - Reflected XSS
CVE-2026-14189
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
CVE-2026-13726
Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
CVE-2026-13714
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution