bashu
3 credited records · 3 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-12949No exploit | Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameterwishlist member · wishlist member · CWE-640 | Critical9.8 | — | 0.5% | Aug 14, 2026 |
35Monitor | CVE-2026-14270No exploit | Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Filthemecomplete · extra checkout options - addon for extra product options plugin · CWE-434 | High8.8 | — | 0.8% | Jul 29, 2026 |
30Monitor | CVE-2026-9713No exploit | Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Uploadking-theme · product designer for woocommerce wordpress | lumise · CWE-89 | High7.5 | — | 0.5% | Jul 23, 2026 |
- CVE-2026-1294939Monitor
Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter
CriticalCVSS 9.8No exploitEPSS 1%wishlist member · wishlist memberAug 14, 2026
- CVE-2026-1427035Monitor
Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Fil
HighCVSS 8.8No exploitEPSS 1%themecomplete · extra checkout options - addon for extra product options pluginJul 29, 2026
- CVE-2026-971330Monitor
Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload
HighCVSS 7.5No exploitEPSS 0%king-theme · product designer for woocommerce wordpress | lumiseJul 23, 2026