← All credits
WPScan
3894 vulnerability records and advisories credit this contributor.
CVE-2026-90988
Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum
CVE-2026-90987
Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
CVE-2026-90952
WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API
CVE-2026-85016
Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter
CVE-2026-85005
Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
CVE-2026-85004
Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
CVE-2026-84740
The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter
CVE-2026-81740
Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback
CVE-2026-79618
WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
CVE-2026-1661
WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection