← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-16746
MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
CVE-2026-16736
User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
CVE-2026-16734
Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation
CVE-2026-16623
Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
CVE-2026-16618
ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
CVE-2026-16613
GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
CVE-2026-16608
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
CVE-2026-16605
MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization