← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-14565
Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration
CVE-2026-14563
Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover
CVE-2026-14562
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure
CVE-2026-14560
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload
CVE-2026-14559
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover
CVE-2025-15695
GTranslate < 3.0.10 - Admin+ Stored XSS
CVE-2026-82925
Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
CVE-2026-81431
Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id
CVE-2026-78361
zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option Deletion
CVE-2026-77771
miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout