Khaled Alenazi

392
All Time Ranking
11
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

11 Vulnerabilities

Title CVE ID CVSS Vector Date
MemberHero – Simple User Registration & Login <= 6.9 - Unauthenticated Privilege Escalation CVE-2026-10522 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L August 31, 2026
Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Privilege Escalation via Administrator Account Takeover CVE-2026-12526 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 31, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Authenticated (Shop Manager+) Remote Code Execution CVE-2026-16576 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H August 28, 2026
SmilePass Selfie Login <= 1.0.2 - Authentication Bypass to Administrator CVE-2026-77002 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 26, 2026
JSON Options <= 0.0.4 - Unauthenticated Remote Code Execution CVE-2026-75860 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 21, 2026
Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Authentication Bypass to Administrator CVE-2026-77001 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 20, 2026
WP Social Media Login <= 1.0.6 - Authentication Bypass to Account Takeover CVE-2026-77000 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 20, 2026
Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation CVE-2026-15215 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L August 3, 2026
Advanced Form Integration <= 2.1.0 - Unauthenticated Privilege Escalation CVE-2026-11794 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H June 10, 2026
Auto x LINE <= 1.0.0 - Missing Authorization CVE-2025-15485 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 13, 2026
Developer Tools <= 1.1.3 - Unauthenticated Arbitrary File Upload CVE-2025-9314 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 21, 2025

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation