← All credits
WPScan
3894 vulnerability records and advisories credit this contributor.
CVE-2026-90953
Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks
CVE-2026-89193
Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
CVE-2026-89190
Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
CVE-2026-88797
Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
CVE-2026-88791
Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
CVE-2026-87777
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
CVE-2026-86789
Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
CVE-2026-85576
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
CVE-2026-85573
All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
CVE-2026-85415
Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL