0xd4rk5id3

Organization: EnvoraSec

22
All Time Ranking
301
All Time Discoveries
6
90 Day Published Submissions
8 Jul '26
Last Published Submission

About

1337 security researcher

Submitted 10 Vulnerabilities
Submitted 10 Vulnerabilities
May 1, 2026
Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
November 27, 2025
Resourceful Researcher
Resourceful Researcher
November 25, 2025
Submitted 1 Vulnerability
Submitted 1 Vulnerability
November 27, 2024
Submitted XSS Vulnerability
Submitted XSS Vulnerability
November 27, 2024

Showing 1-20 of 301 Vulnerabilities

Title CVE ID CVSS Vector Date
Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form CVE-2026-5523 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 8, 2026
Private Content <= 9.9.2 - Unauthenticated Privilege Escalation CVE-2026-57692 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter CVE-2026-5524 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint CVE-2026-12224 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 30, 2026
Themify Popup <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection CVE-2026-56037 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H June 23, 2026
User Registration Stripe <= 1.3.12 - Missing Authorization CVE-2026-49081 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N June 5, 2026
Media folder Addon <= 4.0.1 - Unauthenticated Arbitrary File Download CVE-2026-9690 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H June 4, 2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.1.2 - Missing Authorization CVE-2026-25425 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N May 28, 2026
Events Schedule - WordPress Events Calendar <= 2.7.2 - Authenticated (Subscriber+) SQL Injection CVE-2025-69135 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N May 26, 2026
Felan Framework <= 1.1.3 - Reflected Cross-Site Scripting CVE-2025-22741 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 26, 2026
Entrepreneur - Booking for Small Businesses WordPress <= 3.1.3 - Authenticated (Subscriber+) PHP Object Injection CVE-2025-69130 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H May 26, 2026
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role' CVE-2026-5118 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 20, 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload CVE-2026-4883 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 18, 2026
User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload CVE-2026-4882 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 1, 2026
wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path CVE-2026-6248 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H April 20, 2026
User Registration Stripe <= 1.3.14 - Missing Authorization CVE-2026-40726 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N April 16, 2026
Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication CVE-2026-4880 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 15, 2026
Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email CVE-2026-3461 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 14, 2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution CVE-2026-32488 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 23, 2026
Wishlist Member <= 3.29.0 - Authenticated (Subscriber+) PHP Object Injection CVE-2026-25445 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H March 18, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation