← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-85113
GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name
CVE-2026-85010
RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
CVE-2026-82187
WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Upload
CVE-2026-92541
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer
CVE-2026-92540
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users
CVE-2026-92435
Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
CVE-2026-92430
Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook
CVE-2026-92425
Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR
CVE-2026-92423
Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts
CVE-2026-92422
Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route