← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-13725
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
CVE-2026-13609
Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field
CVE-2026-13604
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
CVE-2026-13596
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
CVE-2026-13393
ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)
CVE-2026-13392
ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)
CVE-2026-13389
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
CVE-2026-13340
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
CVE-2026-13329
WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
CVE-2026-13158
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload