← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-14834
Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX
CVE-2026-14833
Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute
CVE-2026-14830
FlxWoo < 3.1.1 - Unauthenticated Payment Bypass
CVE-2026-14823
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
CVE-2026-14822
Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
CVE-2026-14817
Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
CVE-2026-14596
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
CVE-2026-14561
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
CVE-2026-14557
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
CVE-2026-14554
Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters