← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-19251
Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile Activity
CVE-2026-19116
WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form
CVE-2026-17563
WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form
CVE-2026-14326
Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR
CVE-2026-10821
Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE
CVE-2025-9314
Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload
CVE-2025-8945
Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API
CVE-2025-15692
Icegram Express < 5.8.6 - Admin+ Stored XSS
CVE-2025-15490
Passster < 4.2.26 - Global Protection Bypass
CVE-2025-15489
Passster < 4.2.24 - Password Protection Bypass