← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2026-87970
If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes
CVE-2026-86610
Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon
CVE-2026-81809
Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback
CVE-2026-81739
Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback
CVE-2026-19253
Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url
CVE-2026-101148
BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key
CVE-2026-101147
Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF
CVE-2025-9544
Doppler Forms <= 2.5.1 - Subscriber+ Limited Plugin Installation
CVE-2025-9543
FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS
CVE-2025-8944
OceanWP < 4.1.2 - Subscriber+ Limited Option Update