VDsec
Patchstack Bug Bounty Program
6 credited records · 6 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-32566No exploit | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerabilityacpt · acpt (pro) - custom post types plugin for wordpress · CWE-266 | Critical9.8 | — | 0.5% | Aug 27, 2026 |
34Monitor | CVE-2026-32564No exploit | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerabilityacpt · acpt (pro) - custom post types plugin for wordpress · CWE-89 | High8.5 | — | 0.4% | Aug 27, 2026 |
39Monitor | CVE-2026-32563No exploit | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerabilitya cpt · acpt (pro) - custom post types plugin for wordpress · CWE-502 | Critical9.8 | — | 0.6% | Aug 24, 2026 |
39Monitor | CVE-2026-61967No exploit | WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerabilityminiorange · miniorange otp verification · CWE-640 | Critical9.8 | — | 0.5% | Aug 13, 2026 |
37Monitor | CVE-2026-59514No exploit | WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerabilitymightynetworks vs buddyboss · buddyboss platform · CWE-89 | Critical9.3 | — | 0.4% | Jul 23, 2026 |
29Monitor | CVE-2026-57723No exploit | WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerabilitye4jvikwp · vikbooking hotel booking engine & pms · CWE-352 | High7.4 | — | 0.2% | Jul 1, 2026 |
- CVE-2026-3256639Monitor
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 0%acpt · acpt (pro) - custom post types plugin for wordpressAug 27, 2026
- CVE-2026-3256434Monitor
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerability
HighCVSS 8.5No exploitEPSS 0%acpt · acpt (pro) - custom post types plugin for wordpressAug 27, 2026
- CVE-2026-3256339Monitor
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%a cpt · acpt (pro) - custom post types plugin for wordpressAug 24, 2026
- CVE-2026-6196739Monitor
WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 0%miniorange · miniorange otp verificationAug 13, 2026
- CVE-2026-5951437Monitor
WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%mightynetworks vs buddyboss · buddyboss platformJul 23, 2026
- CVE-2026-5772329Monitor
WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability
HighCVSS 7.4No exploitEPSS 0%e4jvikwp · vikbooking hotel booking engine & pmsJul 1, 2026