← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-13393
ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)
CVE-2026-13392
ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)
CVE-2026-13389
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
CVE-2026-13340
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
CVE-2026-13329
WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
CVE-2026-13158
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
CVE-2026-13157
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVE-2026-12966
Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
CVE-2026-12872
Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
CVE-2026-12721
Kirki < 6.0.13 - Unauthenticated SQL Injection