← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-14333
Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory
CVE-2026-14319
GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
CVE-2026-14317
GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass
CVE-2026-14315
Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
CVE-2026-14309
Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
CVE-2026-14292
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
CVE-2026-14214
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
CVE-2026-14197
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVE-2026-14195
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF