← All credits
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
249 vulnerability records and advisories credit this contributor.
CVE-2026-94678
WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability
CVE-2026-94677
WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability
CVE-2026-94076
WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection vulnerability
CVE-2026-93771
WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injection vulnerability
CVE-2026-93651
WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP Object Injection vulnerability
CVE-2026-93624
WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection vulnerability
CVE-2026-97243
WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerability
CVE-2026-96349
WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability
CVE-2026-96348
WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability
CVE-2026-96347
WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability