← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-87981
Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions
CVE-2026-87979
Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook
CVE-2026-86785
Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update
CVE-2026-77006
WebTotem Backups < 1.1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal
CVE-2026-92965
TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption
CVE-2026-92438
Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin
CVE-2026-92400
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion
CVE-2026-91827
Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export
CVE-2026-88788
Text Styler <= 1.1.1 - Contributor+ Stored XSS
CVE-2026-86802
To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import