← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-89050
Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL
CVE-2026-88995
Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check
CVE-2026-88912
rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Privacy Modification via IDOR
CVE-2026-88802
MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion
CVE-2026-88793
YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server
CVE-2026-88764
Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref
CVE-2026-87919
Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode
CVE-2026-87918
WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions
CVE-2026-87916
WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure
CVE-2026-87894
Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR