← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-15248
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
CVE-2026-15244
HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
CVE-2026-15241
ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
CVE-2026-15236
Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
CVE-2026-15234
Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
CVE-2026-15231
TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
CVE-2026-15209
JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR
CVE-2026-15206
SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
CVE-2026-15151
Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
CVE-2026-15048
GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History