← All credits
WPScan
3893 vulnerability records and advisories credit this contributor.
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVE-2025-15675
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
CVE-2025-15673
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
CVE-2025-15672
Chama < 1.0.13 - Unauthenticated PHP Object Injection
CVE-2025-15669
Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
CVE-2026-11871
Team Showcase Supreme < 9.3 - Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_details
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
CVE-2025-15671
Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter
CVE-2026-93000
SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
CVE-2026-92996
Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done