← All credits
wesley
325 vulnerability records and advisories credit this contributor.
CVE-2025-0394
Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function
CVE-2024-9947
ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider
CVE-2024-9946
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider
CVE-2024-9943
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates
CVE-2024-9893
Nextend Social Login Pro <= 3.1.14 - Authentication Bypass via WordPress.com OAuth provider
CVE-2024-9637
School Management System – WPSchoolPress <= 2.2.10 - Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation
CVE-2024-9636
Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation
CVE-2024-9501
Wp Social Login and Register Social Counter <= 3.0.7 - Authentication Bypass via WordPress.com OAuth provider
CVE-2024-9488
Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider
CVE-2024-9305
AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP