← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-12514
Shared Files < 1.7.70 - Unauthenticated Limited File Upload
CVE-2026-13598
RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-8155
BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
CVE-2026-16540
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
CVE-2026-16292
Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
CVE-2026-16291
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
CVE-2026-16285
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
CVE-2026-16274
Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
CVE-2026-16273
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
CVE-2026-16261
Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover