← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-80440
Hustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success Message Placeholders
CVE-2026-80341
Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment Method Assignment via IDOR
CVE-2026-80340
Payment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PII Disclosure via order-pay
CVE-2026-80339
Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-pay
CVE-2026-75861
Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft and Destruction via Unauthorized Redemption
CVE-2026-19855
Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution via Comment Text
CVE-2026-18042
WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation
CVE-2026-16960
Loops & Logic < 4.3.0 - Unauthenticated User Data and Site Option Disclosure
CVE-2026-14962
ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id
CVE-2026-13146
WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR