← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-14864
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
CVE-2026-14862
Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization
CVE-2026-14849
Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files
CVE-2026-14847
Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR
CVE-2026-14845
NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget
CVE-2026-14843
Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
CVE-2026-14841
King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
CVE-2026-14840
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
CVE-2026-14839
Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
CVE-2026-14836
Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass