← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-19859
JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter
CVE-2026-19858
JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset
CVE-2026-18480
SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover
CVE-2026-15247
Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
CVE-2026-13159
Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation
CVE-2025-15694
Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS
CVE-2025-15693
JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal
CVE-2026-83547
Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets
CVE-2026-83533
WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment
CVE-2026-82884
All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block