← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-84151
The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening
CVE-2026-84091
SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN
CVE-2026-82850
Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure
CVE-2026-82849
Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR
CVE-2026-82195
10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion
CVE-2026-80513
wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields
CVE-2026-80338
CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler
CVE-2026-74991
WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent
CVE-2026-87978
Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback
CVE-2026-87848
MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure