← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-87839
Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion
CVE-2026-87068
Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
CVE-2026-87067
Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection
CVE-2026-86814
UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email
CVE-2026-86591
Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route
CVE-2026-85680
Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title
CVE-2026-85574
Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains
CVE-2026-85017
Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection
CVE-2026-84750
Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Field
CVE-2026-84223
Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload