← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-86788
HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag
CVE-2026-86710
Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter
CVE-2026-86709
The Pressengine <= 1.0 - Unauthenticated Authentication Bypass
CVE-2026-86707
Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter
CVE-2026-86446
LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint
CVE-2026-85350
UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together
CVE-2026-85130
WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
CVE-2026-85128
Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request
CVE-2026-85127
VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment
CVE-2026-85123
Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion