← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-77008
HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings Update
CVE-2026-77007
HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret Disclosure
CVE-2026-76586
BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation
CVE-2026-76585
Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter
CVE-2026-76548
Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass
CVE-2026-76547
Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
CVE-2026-76546
Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode
CVE-2026-19430
CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all
CVE-2026-18234
MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
CVE-2026-18233
MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion