← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-17023
Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
CVE-2026-17022
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
CVE-2026-17021
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering
CVE-2026-17020
Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure
CVE-2026-17019
JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)
CVE-2026-17018
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
CVE-2026-17017
CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation
CVE-2026-17016
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
CVE-2026-17014
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email