Dave Jong (Patchstack)
Patchstack Bug Bounty Program
252 credited records · 7 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2026-28188No exploit | WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerabilitythemefic · hydra booking · CWE-862 | High7.3 | — | 0.3% | Aug 13, 2026 |
26Monitor | CVE-2026-65435No exploit | WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerabilitythrive themes coupon · thrive leads version · CWE-862 | Medium6.5 | — | 0.3% | Jul 27, 2026 |
17Monitor | CVE-2024-54222No exploit | WordPress Seraphinite Accelerator plugin <= 2.22.15 - Authenticated Sensitive Data Exposure vulnerabilityseraphinite solutions · seraphinite accelerator · CWE-862 | Medium4.3 | — | 0.3% | Feb 20, 2026 |
30Monitor | CVE-2023-25446No exploit | WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerabilityhappyfiles · happyfiles pro · CWE-862 | High7.7 | — | 0.4% | Dec 20, 2025 |
21Monitor | CVE-2023-25445No exploit | WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerabilityhappyfiles · happyfiles pro · CWE-862 | Medium5.4 | — | 0.2% | Dec 20, 2025 |
17Monitor | CVE-2023-25068No exploit | WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activationmapro collins · magazine edge · CWE-862 | Medium4.3 | — | 0.2% | Dec 20, 2025 |
21Monitor | CVE-2023-23729No exploit | WordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Contributor+ reCAPTCHA Settings Change Vulnerabilitybrainstorm force · spectra · CWE-862 | Medium5.4 | — | 0.3% | Dec 9, 2025 |
28Monitor | CVE-2025-48333No exploit | WordPress eForm - WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) Vulnerabilitywpquark · eform - wordpress form builder · CWE-79 | High7.1 | — | 0.3% | Jun 17, 2025 |
35Monitor | CVE-2025-39366No exploit | WordPress wProject theme < 5.8.0 - Subscriber+ Privilege Escalation vulnerabilityrocket apps · wproject · CWE-266 | High8.8 | — | 0.3% | May 19, 2025 |
28Monitor | CVE-2025-39365No exploit | WordPress wProject theme < 5.8.0 - Reflected Cross Site Scripting (XSS) vulnerabilityrocket apps · wproject · CWE-79 | High7.1 | — | 0.2% | May 19, 2025 |
32Monitor | CVE-2025-39350No exploit | WordPress wProject theme < 5.8.0 - Unauthenticated Post/Comment/Attachment Modification/Deletion vulnerabilityrocket apps · wproject · CWE-862 | High8.2 | — | 0.3% | May 19, 2025 |
21Monitor | CVE-2023-32240No exploit | WordPress Woodmart theme <= 7.2.1 - Broken Access Control vulnerabilityxtemos · woodmart · CWE-862 | Medium5.4 | — | 0.3% | Jan 2, 2025 |
21Monitor | CVE-2024-37925No exploit | WordPress BuddyBoss Theme theme <= 2.4.61 - Cross Site Request Forgery (CSRF) vulnerabilitybuddyboss llc · buddyboss theme · CWE-352 | Medium5.4 | — | 0.2% | Jan 2, 2025 |
21Monitor | CVE-2024-37438No exploit | WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Cross Site Request Forgery (CSRF) vulnerabilityuncanny owl · uncanny toolkit pro for learndash · CWE-352 | Medium5.4 | — | 0.2% | Jan 2, 2025 |
28Monitor | CVE-2024-56069No exploit | WordPress WP SuperBackup plugin <= 2.3.3 - Reflected Cross Site Scripting (XSS) vulnerabilityazzaroco · wp superbackup · CWE-79 | High7.1 | — | 0.3% | Jan 2, 2025 |
29Monitor | CVE-2024-56070No exploit | WordPress WP SuperBackup plugin <= 2.3.3 - Multiple Subscriber+ Broken Access Control vulnerabilitiesazzaroco · wp superbackup · CWE-862 | High7.4 | — | 0.4% | Dec 31, 2024 |
30Monitor | CVE-2024-56068No exploit | WordPress WP SuperBackup plugin <= 2.3.3 - Subscriber+ PHP Object Injection vulnerabilityazzaroco · wp superbackup · CWE-502 | High7.5 | — | 0.4% | Dec 31, 2024 |
33Monitor | CVE-2024-56067Proof of concept | WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerabilityazzaroco · wp superbackup · CWE-862 | High7.5 | — | 10.0% | Dec 31, 2024 |
49Plan | CVE-2024-56064Proof of concept | WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Arbitrary File Upload vulnerabilityazzaroco · wp superbackup · CWE-434 | Critical10.0 | — | 30.8% | Dec 31, 2024 |
30Monitor | CVE-2023-30490No exploit | WordPress Easing Slider plugin <= 3.0.8 - Plugin Settings Reset Vulnerabilitymatthew ruddy · easing slider · CWE-862 | High7.5 | — | 0.8% | Dec 13, 2024 |
17Monitor | CVE-2023-28990No exploit | WordPress Viral Mag theme <= 1.0.9 - Authenticated Arbitrary Plugin Activation Vulnerabilityhashthemes · viral mag · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
17Monitor | CVE-2023-27456No exploit | WordPress Total theme <= 2.1.19 - Authenticated Arbitrary Plugin Activationhashthemes · total · CWE-862 | Medium4.3 | — | 0.5% | Dec 13, 2024 |
26Monitor | CVE-2024-54218No exploit | WordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Plugin Settings Change vulnerabilitythehp · aio contact · CWE-862 | Medium6.5 | — | 0.3% | Dec 9, 2024 |
28Monitor | CVE-2024-54220No exploit | WordPress FAT Services Booking plugin <= 5.6 - Subscriber+ Site-Wide Cross Site Scripting (XSS) vulnerabilityroninwp · fat services booking · CWE-79 | High7.1 | — | 0.4% | Dec 9, 2024 |
28Monitor | CVE-2024-54219No exploit | WordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Site-Wide Cross Site Scripting (XSS) vulnerabilitythehp · aio contact · CWE-79 | High7.1 | — | 0.4% | Dec 9, 2024 |
- CVE-2026-2818829Monitor
WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability
HighCVSS 7.3No exploitEPSS 0%themefic · hydra bookingAug 13, 2026
- CVE-2026-6543526Monitor
WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%thrive themes coupon · thrive leads versionJul 27, 2026
- CVE-2024-5422217Monitor
WordPress Seraphinite Accelerator plugin <= 2.22.15 - Authenticated Sensitive Data Exposure vulnerability
MediumCVSS 4.3No exploitEPSS 0%seraphinite solutions · seraphinite acceleratorFeb 20, 2026
- CVE-2023-2544630Monitor
WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability
HighCVSS 7.7No exploitEPSS 0%happyfiles · happyfiles proDec 20, 2025
- CVE-2023-2544521Monitor
WordPress HappyFiles Pro plugin <= 1.8.1 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%happyfiles · happyfiles proDec 20, 2025
- CVE-2023-2506817Monitor
WordPress Magazine Edge theme <= 1.13 - Authenticated Arbitrary Plugin Activation
MediumCVSS 4.3No exploitEPSS 0%mapro collins · magazine edgeDec 20, 2025
- CVE-2023-2372921Monitor
WordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Contributor+ reCAPTCHA Settings Change Vulnerability
MediumCVSS 5.4No exploitEPSS 0%brainstorm force · spectraDec 9, 2025
- CVE-2025-4833328Monitor
WordPress eForm - WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) Vulnerability
HighCVSS 7.1No exploitEPSS 0%wpquark · eform - wordpress form builderJun 17, 2025
- CVE-2025-3936635Monitor
WordPress wProject theme < 5.8.0 - Subscriber+ Privilege Escalation vulnerability
HighCVSS 8.8No exploitEPSS 0%rocket apps · wprojectMay 19, 2025
- CVE-2025-3936528Monitor
WordPress wProject theme < 5.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%rocket apps · wprojectMay 19, 2025
- CVE-2025-3935032Monitor
WordPress wProject theme < 5.8.0 - Unauthenticated Post/Comment/Attachment Modification/Deletion vulnerability
HighCVSS 8.2No exploitEPSS 0%rocket apps · wprojectMay 19, 2025
- CVE-2023-3224021Monitor
WordPress Woodmart theme <= 7.2.1 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%xtemos · woodmartJan 2, 2025
- CVE-2024-3792521Monitor
WordPress BuddyBoss Theme theme <= 2.4.61 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 5.4No exploitEPSS 0%buddyboss llc · buddyboss themeJan 2, 2025
- CVE-2024-3743821Monitor
WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 5.4No exploitEPSS 0%uncanny owl · uncanny toolkit pro for learndashJan 2, 2025
- CVE-2024-5606928Monitor
WordPress WP SuperBackup plugin <= 2.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%azzaroco · wp superbackupJan 2, 2025
- CVE-2024-5607029Monitor
WordPress WP SuperBackup plugin <= 2.3.3 - Multiple Subscriber+ Broken Access Control vulnerabilities
HighCVSS 7.4No exploitEPSS 0%azzaroco · wp superbackupDec 31, 2024
- CVE-2024-5606830Monitor
WordPress WP SuperBackup plugin <= 2.3.3 - Subscriber+ PHP Object Injection vulnerability
HighCVSS 7.5No exploitEPSS 0%azzaroco · wp superbackupDec 31, 2024
- CVE-2024-5606733Monitor
WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerability
HighCVSS 7.5Proof of conceptEPSS 10%azzaroco · wp superbackupDec 31, 2024
- CVE-2024-5606449Plan
WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Arbitrary File Upload vulnerability
CriticalCVSS 10.0Proof of conceptEPSS 31%azzaroco · wp superbackupDec 31, 2024
- CVE-2023-3049030Monitor
WordPress Easing Slider plugin <= 3.0.8 - Plugin Settings Reset Vulnerability
HighCVSS 7.5No exploitEPSS 1%matthew ruddy · easing sliderDec 13, 2024
- CVE-2023-2899017Monitor
WordPress Viral Mag theme <= 1.0.9 - Authenticated Arbitrary Plugin Activation Vulnerability
MediumCVSS 4.3No exploitEPSS 0%hashthemes · viral magDec 13, 2024
- CVE-2023-2745617Monitor
WordPress Total theme <= 2.1.19 - Authenticated Arbitrary Plugin Activation
MediumCVSS 4.3No exploitEPSS 0%hashthemes · totalDec 13, 2024
- CVE-2024-5421826Monitor
WordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Plugin Settings Change vulnerability
MediumCVSS 6.5No exploitEPSS 0%thehp · aio contactDec 9, 2024
- CVE-2024-5422028Monitor
WordPress FAT Services Booking plugin <= 5.6 - Subscriber+ Site-Wide Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%roninwp · fat services bookingDec 9, 2024
- CVE-2024-5421928Monitor
WordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Site-Wide Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%thehp · aio contactDec 9, 2024