Skip to content
Noroxi

Mitchell

Patchstack Bug Bounty Program

10 credited records · 10 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler

    MediumCVSS 6.4No exploitEPSS 0%

    appmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker)Sep 19, 2026

  • RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action

    MediumCVSS 6.4No exploitEPSS 0%

    themewant · rt mega menu – mega menu builder for elementor & gutenbergSep 17, 2026

  • Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API

    HighCVSS 7.5No exploitEPSS 1%

    cyberlord92 · page and post restrictionAug 5, 2026

  • WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    xendit · xendit paymentJul 27, 2026

  • WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    aurovrata venet · post my cf7 formJul 27, 2026

  • WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    ziina · ziinaJul 23, 2026

  • WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    fahad mahmood · stock locations for woocommerceJul 13, 2026

  • Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

    MediumCVSS 4.3No exploitEPSS 0%

    subratamal · wallet for woocommerceJul 11, 2026

  • Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter

    HighCVSS 7.5No exploitEPSS 1%

    emarket-design · request a quote – quote forms for any wordpress siteJul 2, 2026

  • WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    wpclever · wpc product options for woocommerceJun 15, 2026