← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-88844
MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR
CVE-2026-88825
iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings
CVE-2026-88798
Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header
CVE-2026-88795
wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token
CVE-2026-88792
Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update
CVE-2026-87966
Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR
CVE-2026-87965
Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token
CVE-2026-87836
Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export
CVE-2026-87831
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field
CVE-2026-87829
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting