← All credits
ifoundbug
16 vulnerability records and advisories credit this contributor.
CVE-2025-10738
URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injection
CVE-2026-2144
Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage
CVE-2025-9985
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
CVE-2025-9984
Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure
CVE-2025-12540
ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure
CVE-2025-12139
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
CVE-2025-11995
Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
CVE-2025-11456
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
CVE-2025-11204
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection
CVE-2025-10754
DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload