← All credits
wesley
325 vulnerability records and advisories credit this contributor.
CVE-2024-13818
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log Files
CVE-2024-13807
Xagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up Files
CVE-2024-13798
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation
CVE-2024-13796
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
CVE-2024-13528
Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode
CVE-2024-13525
Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure
CVE-2024-12919
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id
CVE-2024-12264
PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation
CVE-2024-12118
The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-11293
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth provider