← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-13144
WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset
CVE-2025-15690
Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and Styles
CVE-2026-85038
B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection
CVE-2026-84937
YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax
CVE-2026-84936
EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat
CVE-2026-84935
HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings
CVE-2026-84934
JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
CVE-2026-84931
Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute
CVE-2026-84930
CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
CVE-2026-84146
Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View