← All credits
WPScan
3915 vulnerability records and advisories credit this contributor.
CVE-2026-16542
Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar
CVE-2026-14844
Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes
CVE-2025-15698
Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting
CVE-2026-87963
Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter
CVE-2026-91019
Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure
CVE-2026-91017
Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback
CVE-2026-91016
Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure
CVE-2026-91015
Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired
CVE-2026-91014
Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint
CVE-2026-91011
EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion