← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-84113
Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter
CVE-2026-84068
Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' Parameter
CVE-2026-83541
Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Table Widget
CVE-2026-83537
WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_payment
CVE-2026-82848
Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure
CVE-2026-82185
WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B Test Data Reset
CVE-2026-82184
WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update
CVE-2026-81741
Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
CVE-2026-81022
SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak
CVE-2026-81021
SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure