Deadbee
16 credited records · 16 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
17Monitor | CVE-2026-5582No exploit | FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Togglefusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.) · CWE-352 | Medium4.3 | — | 0.2% | Jul 30, 2026 |
25Monitor | CVE-2026-0736No exploit | Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Fieldcollectchat · chatbot for wordpress by collect.chat ⚡️ · CWE-79 | Medium6.4 | — | 0.3% | Feb 14, 2026 |
28Monitor | CVE-2026-1320No exploit | Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Headerays-pro · secure copy content protection and content locking · CWE-79 | High7.2 | — | 0.3% | Feb 12, 2026 |
21Monitor | CVE-2025-15510No exploit | NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposurewebaways · nex-forms – ultimate forms plugin for wordpress · CWE-862 | Medium5.3 | — | 0.3% | Jan 30, 2026 |
29Monitor | CVE-2026-0832No exploit | New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosuresaadiqbal · new user approve · CWE-862 | High7.3 | — | 0.4% | Jan 28, 2026 |
24Monitor | CVE-2025-14375No exploit | RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via classNamerebelcode · rss aggregator – rss import, news feeds, feed to post, and autoblogging · CWE-79 | Medium6.1 | — | 0.2% | Jan 16, 2026 |
21Monitor | CVE-2025-14507No exploit | EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST APImetagauss · eventprime – events calendar, bookings and tickets · CWE-200 | Medium5.3 | — | 0.4% | Jan 13, 2026 |
21Monitor | CVE-2025-14043No exploit | Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creationtainacan · tainacan · CWE-862 | Medium5.3 | — | 0.3% | Dec 20, 2025 |
17Monitor | CVE-2025-14277No exploit | Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgerybdthemes · prime slider – addons for elementor · CWE-918 | Medium4.3 | — | 0.3% | Dec 18, 2025 |
21Monitor | CVE-2025-14442No exploit | Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export Fileays-pro · secure copy content protection and content locking · CWE-552 | Medium5.3 | — | 0.3% | Dec 12, 2025 |
17Monitor | CVE-2025-14159No exploit | Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Exportays-pro · secure copy content protection and content locking · CWE-352 | Medium4.3 | — | 0.2% | Dec 12, 2025 |
21Monitor | CVE-2025-13006No exploit | SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposurewpeka-club · surveyfunnel – survey plugin for wordpress · CWE-200 | Medium5.3 | — | 0.3% | Dec 5, 2025 |
17Monitor | CVE-2025-13685No exploit | Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actionsays-pro · photo gallery by ays – responsive image gallery · CWE-352 | Medium4.3 | — | 0.2% | Dec 2, 2025 |
17Monitor | CVE-2025-13143No exploit | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnectionassafp · quiz, poll & survey maker by opinion stage · CWE-352 | Medium4.3 | — | 0.2% | Nov 27, 2025 |
21Monitor | CVE-2025-12747No exploit | Tainacan <= 1.0.0 - Unauthenticated Information Exposuretainacan · tainacan · CWE-552 | Medium5.3 | — | 0.3% | Nov 21, 2025 |
24Monitor | CVE-2025-12746No exploit | Tainacan <= 1.0.0 - Reflected Cross-Site Scriptingtainacan · tainacan · CWE-79 | Medium6.1 | — | 0.3% | Nov 21, 2025 |
- CVE-2026-558217Monitor
FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle
MediumCVSS 4.3No exploitEPSS 0%fusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.)Jul 30, 2026
- CVE-2026-073625Monitor
Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field
MediumCVSS 6.4No exploitEPSS 0%collectchat · chatbot for wordpress by collect.chat ⚡️Feb 14, 2026
- CVE-2026-132028Monitor
Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
HighCVSS 7.2No exploitEPSS 0%ays-pro · secure copy content protection and content lockingFeb 12, 2026
- CVE-2025-1551021Monitor
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure
MediumCVSS 5.3No exploitEPSS 0%webaways · nex-forms – ultimate forms plugin for wordpressJan 30, 2026
- CVE-2026-083229Monitor
New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure
HighCVSS 7.3No exploitEPSS 0%saadiqbal · new user approveJan 28, 2026
- CVE-2025-1437524Monitor
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className
MediumCVSS 6.1No exploitEPSS 0%rebelcode · rss aggregator – rss import, news feeds, feed to post, and autobloggingJan 16, 2026
- CVE-2025-1450721Monitor
EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API
MediumCVSS 5.3No exploitEPSS 0%metagauss · eventprime – events calendar, bookings and ticketsJan 13, 2026
- CVE-2025-1404321Monitor
Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation
MediumCVSS 5.3No exploitEPSS 0%tainacan · tainacanDec 20, 2025
- CVE-2025-1427717Monitor
Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery
MediumCVSS 4.3No exploitEPSS 0%bdthemes · prime slider – addons for elementorDec 18, 2025
- CVE-2025-1444221Monitor
Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File
MediumCVSS 5.3No exploitEPSS 0%ays-pro · secure copy content protection and content lockingDec 12, 2025
- CVE-2025-1415917Monitor
Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export
MediumCVSS 4.3No exploitEPSS 0%ays-pro · secure copy content protection and content lockingDec 12, 2025
- CVE-2025-1300621Monitor
SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure
MediumCVSS 5.3No exploitEPSS 0%wpeka-club · surveyfunnel – survey plugin for wordpressDec 5, 2025
- CVE-2025-1368517Monitor
Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions
MediumCVSS 4.3No exploitEPSS 0%ays-pro · photo gallery by ays – responsive image galleryDec 2, 2025
- CVE-2025-1314317Monitor
Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection
MediumCVSS 4.3No exploitEPSS 0%assafp · quiz, poll & survey maker by opinion stageNov 27, 2025
- CVE-2025-1274721Monitor
Tainacan <= 1.0.0 - Unauthenticated Information Exposure
MediumCVSS 5.3No exploitEPSS 0%tainacan · tainacanNov 21, 2025
- CVE-2025-1274624Monitor
Tainacan <= 1.0.0 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%tainacan · tainacanNov 21, 2025