Shikhali Jamalzade

254
All Time Ranking
20
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

20 Vulnerabilities

Title CVE ID CVSS Vector Date
Ultimate Gift Cards for WooCommerce <= 3.2.9 - Missing Authorization CVE-2026-75861 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N September 7, 2026
CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce < 6.1.3 - Unauthenticated Email Content Injection CVE-2026-79621 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 31, 2026
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions 5.0.13 - 5.0.14 - Unauthenticated Information Exposure CVE-2026-74927 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 31, 2026
Catfolders Document Gallery Pro < 2.0.7 - Missing Authorization CVE-2026-19430 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 29, 2026
StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation CVE-2026-78137 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 28, 2026
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.2.4 - Authenticated (Contributor+) Insecure Direct Object Reference CVE-2026-79615 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N August 28, 2026
Return Refund and Exchange For WooCommerce < 4.6.4 - Missing Authorization CVE-2026-77695 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 28, 2026
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist < 3.1.4 - Authenticated (Subscriber+) Insecure Direct Object Reference CVE-2026-78139 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N August 27, 2026
Finale Lite – Sales Countdown Timer & Discount for WooCommerce < 2.21.0 - Authenticated (Subscriber+) Information Exposure CVE-2026-78138 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 27, 2026
WCFM Marketplace – Multivendor Marketplace for WooCommerce < 3.8.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Refund Request CVE-2026-77701 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 26, 2026
LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Information Exposure CVE-2026-78125 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 25, 2026
Order Tip for WooCommerce < 1.6.0 - Authenticated (Shop Manager+) Arbitrary File Deletion CVE-2026-77693 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H August 24, 2026
Easy Appointments < 4.0.1 - Authenticated (Contributor+) Information Exposure CVE-2026-19406 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 21, 2026
WPS Bidouille < 1.33.5 - Authenticated (Subscriber+) Information Exposure CVE-2026-19782 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 21, 2026
Membership For WooCommerce < 3.1.2 - Unauthenticated Information Exposure CVE-2026-19709 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 21, 2026
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor <= 2.4.15 - Authenticated (Contributor+) Information Exposure CVE-2026-19699 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 21, 2026
CatFolders Document Gallery & PDF Library < 2.0.7 - Missing Authorization CVE-2026-19717 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 20, 2026
Advanced Classifieds & Directory Pro <= 3.4.2 - Unauthenticated Non-Public Listing Custom Field Disclosure CVE-2026-19074 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 7, 2026
MLS Import <= 7.0.3 - Authenticated (Subscriber+) Information Exposure CVE-2026-17515 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N July 29, 2026
REST API Log <= 1.7.0 - Missing Authorization to Unauthenticated Sensitive Log Data Disclosure CVE-2026-16547 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N July 27, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation