← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-87786
Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates
CVE-2026-87775
Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell
CVE-2026-87774
Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week
CVE-2026-87771
Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read
CVE-2026-87770
Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product
CVE-2026-87767
WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url
CVE-2026-86824
Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key
CVE-2026-86801
To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler
CVE-2026-86800
WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check
CVE-2026-86796
WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters