← All credits
WPScan
3924 vulnerability records and advisories credit this contributor.
CVE-2026-14835
SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox
CVE-2026-14307
Geotargeting WP < 3.5.6.2 - Reflected XSS
CVE-2026-12965
Super Store Finder < 7.11 - Unauthenticated SQL Injection via ssf_tracking
CVE-2026-16739
Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery
CVE-2026-78333
12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log
CVE-2026-78139
Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR
CVE-2026-78138
Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
CVE-2026-78137
StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart
CVE-2026-78125
LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure
CVE-2026-77018
Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment