109
All Time Ranking
51
All Time Discoveries
1
90 Day Published Submissions
26 May '26
Last Published Submission

About

Just me and just me, idk lol qkqkqkqk

Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
January 6, 2026
Submitted 1 Vulnerability
Submitted 1 Vulnerability
November 4, 2025

Showing 1-20 of 51 Vulnerabilities

Title CVE ID CVSS Vector Date
Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter CVE-2025-14481 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N May 26, 2026
bunny.net – WordPress CDN Plugin <= 2.3.6 - Missing Authorization CVE-2025-68049 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N May 7, 2026
WPJAM Basic <= 6.9.2 - Authenticated (Subscriber+) Arbitrary File Upload CVE-2026-32523 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 20, 2026
Widget Wrangler <= 2.3.9 - Authenticated (Author+) Remote Code Execution CVE-2026-25447 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 18, 2026
Activity Log for WordPress <= 1.2.7 - Missing Authorization CVE-2026-24987 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N March 17, 2026
Mobile App Editor – WordPress to Android App Builder <= 1.3.1 - Authenticated (Editor+) Arbitrary File Upload CVE-2026-27067 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H March 12, 2026
PitchPrint <= 11.1.2 - Unauthenticated Arbitrary File Deletion CVE-2026-22448 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H March 10, 2026
WBW Currency Switcher for WooCommerce <= 2.2.5 - Missing Authorization CVE-2026-32410 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 23, 2026
Aruba HiSpeed Cache <= 3.0.4 - Missing Authorization CVE-2026-23545 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 18, 2026
leadlovers forms <= 1.0.2 - Missing Authorization CVE-2026-39657 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 16, 2026
Download Manager Addons for Elementor <= 1.3.0 - Unauthenticated SQL Injection CVE-2026-24956 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N February 11, 2026
LottieFiles <= 3.0.0 - Missing Authorization CVE-2025-68043 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H February 5, 2026
Plugin BlueX for WooCommerce <= 3.1.4 - Missing Authorization CVE-2025-68022 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 4, 2026
Sync Master Sheet – Product Sync with Google Sheet for WooCommerce <= 1.1.3 - Missing Authorization CVE-2025-68834 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 4, 2026
Authorsy <= 1.0.6 - Unauthenticated Insecure Direct Object Reference CVE-2026-24950 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N February 3, 2026
Shiprocket <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference CVE-2025-68051 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N January 29, 2026
WPLegalPages <= 3.5.4 - Missing Authorization CVE-2025-67974 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 27, 2026
Leadpages <= 1.1.3 - Missing Authorization CVE-2025-68050 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 27, 2026
ConveyThis <= 270.4 - Missing Authorization CVE-2025-68021 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 27, 2026
NextMove Lite <= 2.23.0 - Missing Authorization CVE-2025-68048 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N January 27, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation