← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-18603
Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX Actions
CVE-2026-18473
WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter
CVE-2026-18470
Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response
CVE-2026-18469
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force
CVE-2026-18468
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header
CVE-2026-18465
WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion
CVE-2026-18464
WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
CVE-2026-18395
Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
CVE-2026-18357
WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure
CVE-2026-18200
FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update