← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-86602
WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview
CVE-2026-86601
WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content
CVE-2026-85006
Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget
CVE-2026-84743
The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
CVE-2026-84742
The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API
CVE-2026-84741
The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API
CVE-2026-84168
Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure
CVE-2026-84150
Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint
CVE-2026-84098
Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing
CVE-2026-84046
Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL