← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-96899
Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
CVE-2026-96897
Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache
CVE-2026-96896
Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request
CVE-2026-96895
WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
CVE-2026-96533
Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL
CVE-2026-96532
Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update
CVE-2026-96531
Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block
CVE-2026-96526
MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route
CVE-2026-96525
MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Missing Ownership Check
CVE-2026-96524
MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF