0xd4rk5id3

Organization: EnvoraSec

24
All Time Ranking
311
All Time Discoveries
9
90 Day Published Submissions
4 Sep '26
Last Published Submission

About

1337 security researcher

Submitted 10 Vulnerabilities
Submitted 10 Vulnerabilities
May 1, 2026
Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
November 27, 2025
Resourceful Researcher
Resourceful Researcher
November 25, 2025
Submitted 1 Vulnerability
Submitted 1 Vulnerability
November 27, 2024
Submitted XSS Vulnerability
Submitted XSS Vulnerability
November 27, 2024

Showing 1-20 of 311 Vulnerabilities

Title CVE ID CVSS Vector Date
WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter CVE-2026-14975 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N September 4, 2026
WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter CVE-2026-14982 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H September 1, 2026
Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout CVE-2026-15369 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 29, 2026
WordPress & WooCommerce Affiliate Program <= 8.9.1 - Unauthenticated Privilege Escalation CVE-2026-32558 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L August 24, 2026
User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 5.4.5 - Unauthenticated Privilege Escalation via Account Takeover CVE-2026-74001 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 19, 2026
Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision CVE-2026-15142 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H August 14, 2026
Piotnet Addons For Elementor Pro <= 7.1.67 - Unauthenticated Arbitrary File Upload CVE-2026-28192 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 13, 2026
Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter CVE-2026-14955 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N July 24, 2026
Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter CVE-2026-14956 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 16, 2026
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.3 - Unauthenticated Arbitrary File Upload CVE-2026-57719 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 9, 2026
Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form CVE-2026-5523 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H July 8, 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter CVE-2026-5524 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Private Content <= 9.9.2 - Unauthenticated Privilege Escalation CVE-2026-57692 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 1, 2026
Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint CVE-2026-12224 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 30, 2026
Themify Popup <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection CVE-2026-56037 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H June 23, 2026
User Registration Stripe <= 1.3.12 - Missing Authorization CVE-2026-49081 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N June 5, 2026
Media folder Addon <= 4.0.1 - Unauthenticated Arbitrary File Download CVE-2026-9690 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H June 4, 2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.1.2 - Missing Authorization CVE-2026-25425 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N May 28, 2026
Entrepreneur - Booking for Small Businesses WordPress <= 3.1.3 - Authenticated (Subscriber+) PHP Object Injection CVE-2025-69130 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H May 26, 2026
Felan Framework <= 1.1.3 - Reflected Cross-Site Scripting CVE-2025-22741 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 26, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation