← All credits
WPScan
3974 vulnerability records and advisories credit this contributor.
CVE-2026-16583
Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
CVE-2026-16578
Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
CVE-2026-16574
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
CVE-2026-16573
Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
CVE-2026-16572
LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
CVE-2026-16565
Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
CVE-2026-16564
Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
CVE-2026-16563
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
CVE-2026-16562
WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
CVE-2026-16561
Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure