← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-18364
Zportals < 6.4.2 - Subscriber+ Arbitrary Plugin Settings Update
CVE-2026-16264
Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR
CVE-2026-14321
Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing
CVE-2025-15696
Real3D Flipbook Lite < 5.4 - Author+ Stored XSS
CVE-2022-4997
JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Payment Token
CVE-2026-93528
NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page
CVE-2026-93511
Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass
CVE-2026-93510
Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Balance Manipulation via assign_claim_points
CVE-2026-93508
WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX
CVE-2026-93507
WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure