0xd4rk5id3

Organization: EnvoraSec

24
All Time Ranking
310
All Time Discoveries
9
90 Day Published Submissions
4 Sep '26
Last Published Submission

About

1337 security researcher

Submitted 10 Vulnerabilities
Submitted 10 Vulnerabilities
May 1, 2026
Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
November 27, 2025
Resourceful Researcher
Resourceful Researcher
November 25, 2025
Submitted 1 Vulnerability
Submitted 1 Vulnerability
November 27, 2024
Submitted XSS Vulnerability
Submitted XSS Vulnerability
November 27, 2024

Showing 1-20 of 310 Vulnerabilities

Title CVE ID CVSS Vector Date
Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout CVE-2026-15369 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 29, 2026
User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 5.4.5 - Unauthenticated Privilege Escalation via Account Takeover CVE-2026-74001 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 19, 2026
Piotnet Addons For Elementor Pro <= 7.1.67 - Unauthenticated Arbitrary File Upload CVE-2026-28192 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 13, 2026
Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter CVE-2026-14956 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 16, 2026
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.3 - Unauthenticated Arbitrary File Upload CVE-2026-57719 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 9, 2026
Private Content <= 9.9.2 - Unauthenticated Privilege Escalation CVE-2026-57692 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter CVE-2026-5524 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role' CVE-2026-5118 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 20, 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload CVE-2026-4883 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 18, 2026
User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload CVE-2026-4882 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H May 1, 2026
Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication CVE-2026-4880 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 15, 2026
Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email CVE-2026-3461 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 14, 2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution CVE-2026-32488 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 23, 2026
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authentication Bypass CVE-2026-24373 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 12, 2026
LazyTasks <= 1.2.37 - Unauthenticated Privilege Escalation CVE-2025-68869 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H January 22, 2026
Directorist Social Login <= 2.1.1 - Unauthenticated Privilege Escalation CVE-2026-22337 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H January 20, 2026
Miraculous Core <= 2.0.7 - Unauthenticated Privilege Escalation CVE-2025-49388 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 21, 2025
Custom User Registration Fields for WooCommerce <= 2.1.2 - Unauthenticated Arbitrary File Upload CVE-2025-60207 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 14, 2025
Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Unauthenticated Arbitrary File Upload CVE-2025-29009 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 11, 2025
Helpdesk Support Ticket System for WooCommerce <= 2.1.0 - Unauthenticated Arbitrary File Upload CVE-2025-60235 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 11, 2025

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation