← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-76550
WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal
CVE-2026-74926
MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint
CVE-2026-86475
Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission
CVE-2026-84906
Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay
CVE-2026-19857
Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token
CVE-2026-18232
WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindow
CVE-2026-16593
WP Directory Kit <= 1.5.7 - Editor+ SQL Injection via Elementor Category and Location Widget Settings
CVE-2026-16592
WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via Shortcodes
CVE-2026-13407
Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails
CVE-2026-89080
Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion