Bonds
Patchstack Bug Bounty Program
451 credited records · 320 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2026-27347No exploit | WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerabilitycrocoblock · jetpopup · CWE-862 | Medium5.3 | — | 0.3% | Sep 4, 2026 |
28Monitor | CVE-2026-66623No exploit | WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerabilityinisev · social media & share icons · CWE-79 | High7.1 | — | 0.3% | Aug 24, 2026 |
32Monitor | CVE-2025-15637No exploit | WordPress Shuffle theme <= 1.8 - Local File Inclusion vulnerabilityedge themes · shuffle · CWE-98 | High8.1 | — | 0.5% | Aug 20, 2026 |
40Plan | CVE-2026-66665No exploit | WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerabilitybrandexponents · type hub · CWE-434 | Critical10.0 | — | 0.5% | Aug 6, 2026 |
39Monitor | CVE-2026-65579No exploit | WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerabilityaxiomthemes · agricola · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65578No exploit | WordPress Agora theme <= 1.9 - PHP Object Injection vulnerabilityancorathemes · agora · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65577No exploit | WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerabilityancorathemes · advice · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65576No exploit | WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerabilityancorathemes · adrena · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65574No exploit | WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerabilityancorathemes · abogado · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65572No exploit | WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerabilityaxiomthemes · a.williams · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
39Monitor | CVE-2026-65571No exploit | WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerabilityaxiomthemes · 69 clothing · CWE-502 | Critical9.8 | — | 0.6% | Aug 6, 2026 |
37Monitor | CVE-2026-65546No exploit | WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerabilityqode · qode tours · CWE-89 | Critical9.3 | — | 0.4% | Aug 6, 2026 |
17Monitor | CVE-2026-65524No exploit | WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerabilitythemefusion · avada custom branding · CWE-862 | Medium4.3 | — | 0.3% | Jul 23, 2026 |
28Monitor | CVE-2026-57745No exploit | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerabilitystmcan · rt-theme 18 | extensions · CWE-79 | High7.1 | — | 0.3% | Jul 13, 2026 |
39Monitor | CVE-2026-57744No exploit | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerabilitystmcan · rt-theme 18 | extensions · CWE-502 | Critical9.8 | — | 0.6% | Jul 13, 2026 |
32Monitor | CVE-2026-57743No exploit | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerabilitystmcan · rt-theme 18 | extensions · CWE-98 | High8.1 | — | 0.6% | Jul 13, 2026 |
39Monitor | CVE-2026-57738No exploit | WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerabilityaxiomthemes · 777 · CWE-502 | Critical9.8 | — | 0.6% | Jul 13, 2026 |
28Monitor | CVE-2026-57734No exploit | WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerabilitytagdiv · tagdiv composer · CWE-79 | High7.1 | — | 0.3% | Jul 13, 2026 |
28Monitor | CVE-2026-57733No exploit | WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerabilitytagdiv · tagdiv cloud library · CWE-79 | High7.1 | — | 0.3% | Jul 13, 2026 |
28Monitor | CVE-2026-57732No exploit | WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerabilitytagdiv · tagdiv opt-in builder · CWE-79 | High7.1 | — | 0.3% | Jul 13, 2026 |
30Monitor | CVE-2026-57729No exploit | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerabilityux-themes · flatsome · CWE-862 | High7.5 | — | 0.4% | Jul 13, 2026 |
28Monitor | CVE-2026-57728No exploit | WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerabilityux-themes · flatsome · CWE-79 | High7.1 | — | 0.3% | Jul 13, 2026 |
26Monitor | CVE-2026-57731No exploit | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerabilityux-themes · flatsome · CWE-862 | Medium6.5 | — | 0.3% | Jul 2, 2026 |
17Monitor | CVE-2026-57730No exploit | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerabilityux-themes · flatsome · CWE-862 | Medium4.3 | — | 0.3% | Jul 2, 2026 |
26Monitor | CVE-2025-69132No exploit | WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerabilityzozothemes · corpkit · CWE-201 | Medium6.5 | — | 0.4% | Jul 2, 2026 |
- CVE-2026-2734721Monitor
WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%crocoblock · jetpopupSep 4, 2026
- CVE-2026-6662328Monitor
WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%inisev · social media & share iconsAug 24, 2026
- CVE-2025-1563732Monitor
WordPress Shuffle theme <= 1.8 - Local File Inclusion vulnerability
HighCVSS 8.1No exploitEPSS 0%edge themes · shuffleAug 20, 2026
- CVE-2026-6666540Plan
WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
CriticalCVSS 10.0No exploitEPSS 1%brandexponents · type hubAug 6, 2026
- CVE-2026-6557939Monitor
WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%axiomthemes · agricolaAug 6, 2026
- CVE-2026-6557839Monitor
WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ancorathemes · agoraAug 6, 2026
- CVE-2026-6557739Monitor
WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ancorathemes · adviceAug 6, 2026
- CVE-2026-6557639Monitor
WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ancorathemes · adrenaAug 6, 2026
- CVE-2026-6557439Monitor
WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ancorathemes · abogadoAug 6, 2026
- CVE-2026-6557239Monitor
WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%axiomthemes · a.williamsAug 6, 2026
- CVE-2026-6557139Monitor
WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%axiomthemes · 69 clothingAug 6, 2026
- CVE-2026-6554637Monitor
WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%qode · qode toursAug 6, 2026
- CVE-2026-6552417Monitor
WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%themefusion · avada custom brandingJul 23, 2026
- CVE-2026-5774528Monitor
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%stmcan · rt-theme 18 | extensionsJul 13, 2026
- CVE-2026-5774439Monitor
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%stmcan · rt-theme 18 | extensionsJul 13, 2026
- CVE-2026-5774332Monitor
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability
HighCVSS 8.1No exploitEPSS 1%stmcan · rt-theme 18 | extensionsJul 13, 2026
- CVE-2026-5773839Monitor
WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%axiomthemes · 777Jul 13, 2026
- CVE-2026-5773428Monitor
WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%tagdiv · tagdiv composerJul 13, 2026
- CVE-2026-5773328Monitor
WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%tagdiv · tagdiv cloud libraryJul 13, 2026
- CVE-2026-5773228Monitor
WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%tagdiv · tagdiv opt-in builderJul 13, 2026
- CVE-2026-5772930Monitor
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%ux-themes · flatsomeJul 13, 2026
- CVE-2026-5772828Monitor
WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%ux-themes · flatsomeJul 13, 2026
- CVE-2026-5773126Monitor
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%ux-themes · flatsomeJul 2, 2026
- CVE-2026-5773017Monitor
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%ux-themes · flatsomeJul 2, 2026
- CVE-2025-6913226Monitor
WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
MediumCVSS 6.5No exploitEPSS 0%zozothemes · corpkitJul 2, 2026