← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-16559
YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
CVE-2026-16558
YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
CVE-2026-16548
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
CVE-2026-16547
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
CVE-2026-16546
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
CVE-2026-16539
SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
CVE-2026-16537
Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
CVE-2026-16536
Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id
CVE-2026-16535
Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
CVE-2026-16534
Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import