← All credits

wesley

325 vulnerability records and advisories credit this contributor.

CVE-2025-3292
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update
CVE-2025-3284
User Registration & Membership PRO – Custom Registration Form, Login Form, and User Profile <= 5.1.3 - Cross-Site Request Forgery to User Deletion
CVE-2025-3282
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification
CVE-2025-3281
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
CVE-2025-2228
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure
CVE-2025-2221
WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
CVE-2025-1770
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion
CVE-2025-1766
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update
CVE-2025-1670
School Management System – WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection
CVE-2025-1669
School Management System – WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection