Skip to content
Noroxi

Deadbee

16 credited records · 16 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • CVE-2026-5582
    17Monitor

    FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle

    MediumCVSS 4.3No exploitEPSS 0%

    fusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.)Jul 30, 2026

  • CVE-2026-0736
    25Monitor

    Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field

    MediumCVSS 6.4No exploitEPSS 0%

    collectchat · chatbot for wordpress by collect.chat ⚡️Feb 14, 2026

  • CVE-2026-1320
    28Monitor

    Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

    HighCVSS 7.2No exploitEPSS 0%

    ays-pro · secure copy content protection and content lockingFeb 12, 2026

  • NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    MediumCVSS 5.3No exploitEPSS 0%

    webaways · nex-forms – ultimate forms plugin for wordpressJan 30, 2026

  • CVE-2026-0832
    29Monitor

    New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure

    HighCVSS 7.3No exploitEPSS 0%

    saadiqbal · new user approveJan 28, 2026

  • RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className

    MediumCVSS 6.1No exploitEPSS 0%

    rebelcode · rss aggregator – rss import, news feeds, feed to post, and autobloggingJan 16, 2026

  • EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API

    MediumCVSS 5.3No exploitEPSS 0%

    metagauss · eventprime – events calendar, bookings and ticketsJan 13, 2026

  • Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation

    MediumCVSS 5.3No exploitEPSS 0%

    tainacan · tainacanDec 20, 2025

  • Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery

    MediumCVSS 4.3No exploitEPSS 0%

    bdthemes · prime slider – addons for elementorDec 18, 2025

  • Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File

    MediumCVSS 5.3No exploitEPSS 0%

    ays-pro · secure copy content protection and content lockingDec 12, 2025

  • Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export

    MediumCVSS 4.3No exploitEPSS 0%

    ays-pro · secure copy content protection and content lockingDec 12, 2025

  • SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure

    MediumCVSS 5.3No exploitEPSS 0%

    wpeka-club · surveyfunnel – survey plugin for wordpressDec 5, 2025

  • Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions

    MediumCVSS 4.3No exploitEPSS 0%

    ays-pro · photo gallery by ays – responsive image galleryDec 2, 2025

  • Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection

    MediumCVSS 4.3No exploitEPSS 0%

    assafp · quiz, poll & survey maker by opinion stageNov 27, 2025

  • Tainacan <= 1.0.0 - Unauthenticated Information Exposure

    MediumCVSS 5.3No exploitEPSS 0%

    tainacan · tainacanNov 21, 2025

  • Tainacan <= 1.0.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    tainacan · tainacanNov 21, 2025