← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-90978
Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check
CVE-2026-90977
Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
CVE-2026-90976
Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled
CVE-2026-90923
Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion
CVE-2026-90922
Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch
CVE-2026-89008
Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure
CVE-2026-89007
Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization
CVE-2026-88994
All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes
CVE-2026-88993
All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute
CVE-2026-88904
PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation