← All credits
WPScan
3954 vulnerability records and advisories credit this contributor.
CVE-2026-16282
Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
CVE-2026-16276
Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
CVE-2026-16269
Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
CVE-2026-16268
Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
CVE-2026-16267
Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
CVE-2026-16265
WP Maps < 4.9.7 - Subscriber+ Denial of Service
CVE-2026-16263
WP Maps < 4.9.7 - Subscriber+ Local File Inclusion
CVE-2026-16262
Estatik < 4.3.3 - Login CSRF
CVE-2026-16258
Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
CVE-2026-16257
Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling