← All credits
WPScan
3921 vulnerability records and advisories credit this contributor.
CVE-2026-83546
CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute
CVE-2026-83545
CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON
CVE-2026-82305
YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title
CVE-2026-82215
WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified Webhook
CVE-2026-82213
Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR
CVE-2026-74925
MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator
CVE-2026-14566
Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering
CVE-2026-14565
Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration
CVE-2026-14563
Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover
CVE-2026-14562
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure