Skip to content
Noroxi

VDsec

Patchstack Bug Bounty Program

6 credited records · 6 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    acpt · acpt (pro) - custom post types plugin for wordpressAug 27, 2026

  • WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    acpt · acpt (pro) - custom post types plugin for wordpressAug 27, 2026

  • WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    a cpt · acpt (pro) - custom post types plugin for wordpressAug 24, 2026

  • WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    miniorange · miniorange otp verificationAug 13, 2026

  • WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    mightynetworks vs buddyboss · buddyboss platformJul 23, 2026

  • WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability

    HighCVSS 7.4No exploitEPSS 0%

    e4jvikwp · vikbooking hotel booking engine & pmsJul 1, 2026