← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-77009
WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
CVE-2026-74927
MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint
CVE-2026-4357
Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload
CVE-2026-2811
Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
CVE-2026-2688
CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass
CVE-2026-19723
Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler
CVE-2026-19719
Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title
CVE-2026-19704
Comments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi
CVE-2026-19698
GutenKit < 2.5.1 - Contributor+ Stored CSS Injection
CVE-2026-19453
JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection