← All credits
Dmitrii ignatyev
414 vulnerability records and advisories credit this contributor.
CVE-2026-92767
Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute
CVE-2026-97317
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page
CVE-2026-87777
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
CVE-2026-96895
WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
CVE-2026-97227
NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
CVE-2026-97319
PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
CVE-2026-96531
Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block
CVE-2026-92746
Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute
CVE-2026-12995
Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter
CVE-2026-85410
Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter