Mitchell
Patchstack Bug Bounty Program
10 credited records · 10 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
25Monitor | CVE-2026-13770No exploit | AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handlerappmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker) · CWE-79 | Medium6.4 | — | 0.2% | Sep 19, 2026 |
25Monitor | CVE-2026-14855No exploit | RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Actionthemewant · rt mega menu – mega menu builder for elementor & gutenberg · CWE-79 | Medium6.4 | — | 0.2% | Sep 17, 2026 |
30Monitor | CVE-2026-12000No exploit | Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST APIcyberlord92 · page and post restriction · CWE-862 | High7.5 | — | 0.7% | Aug 5, 2026 |
30Monitor | CVE-2026-66473No exploit | WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerabilityxendit · xendit payment · CWE-862 | High7.5 | — | 0.3% | Jul 27, 2026 |
30Monitor | CVE-2026-59534No exploit | WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerabilityaurovrata venet · post my cf7 form · CWE-862 | High7.5 | — | 0.3% | Jul 27, 2026 |
30Monitor | CVE-2026-59554No exploit | WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerabilityziina · ziina · CWE-1390 | High7.5 | — | 0.4% | Jul 23, 2026 |
26Monitor | CVE-2026-57419No exploit | WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerabilityfahad mahmood · stock locations for woocommerce · CWE-862 | Medium6.5 | — | 0.3% | Jul 13, 2026 |
17Monitor | CVE-2026-12103No exploit | Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Actionsubratamal · wallet for woocommerce · CWE-862 | Medium4.3 | — | 0.5% | Jul 11, 2026 |
30Monitor | CVE-2026-14249No exploit | Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameteremarket-design · request a quote – quote forms for any wordpress site · CWE-74 | High7.5 | — | 0.6% | Jul 2, 2026 |
30Monitor | CVE-2026-49061No exploit | WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilitywpclever · wpc product options for woocommerce · CWE-22 | High7.5 | — | 0.5% | Jun 15, 2026 |
- CVE-2026-1377025Monitor
AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler
MediumCVSS 6.4No exploitEPSS 0%appmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker)Sep 19, 2026
- CVE-2026-1485525Monitor
RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action
MediumCVSS 6.4No exploitEPSS 0%themewant · rt mega menu – mega menu builder for elementor & gutenbergSep 17, 2026
- CVE-2026-1200030Monitor
Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
HighCVSS 7.5No exploitEPSS 1%cyberlord92 · page and post restrictionAug 5, 2026
- CVE-2026-6647330Monitor
WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%xendit · xendit paymentJul 27, 2026
- CVE-2026-5953430Monitor
WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%aurovrata venet · post my cf7 formJul 27, 2026
- CVE-2026-5955430Monitor
WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
HighCVSS 7.5No exploitEPSS 0%ziina · ziinaJul 23, 2026
- CVE-2026-5741926Monitor
WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%fahad mahmood · stock locations for woocommerceJul 13, 2026
- CVE-2026-1210317Monitor
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
MediumCVSS 4.3No exploitEPSS 0%subratamal · wallet for woocommerceJul 11, 2026
- CVE-2026-1424930Monitor
Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
HighCVSS 7.5No exploitEPSS 1%emarket-design · request a quote – quote forms for any wordpress siteJul 2, 2026
- CVE-2026-4906130Monitor
WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability
HighCVSS 7.5No exploitEPSS 1%wpclever · wpc product options for woocommerceJun 15, 2026