← All credits
WPScan
3930 vulnerability records and advisories credit this contributor.
CVE-2026-13157
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVE-2026-12966
Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
CVE-2026-12872
Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
CVE-2026-12721
Kirki < 6.0.13 - Unauthenticated SQL Injection
CVE-2026-12720
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
CVE-2026-12697
wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
CVE-2026-12696
wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
CVE-2026-12695
miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret
CVE-2026-12586
Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
CVE-2026-12376
Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint