NumeX
Patchstack Bug Bounty Program
51 credited records · 50 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-15291No exploit | Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposurethemeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat form · CWE-862 | High7.5 | — | 0.7% | Jul 10, 2026 |
25Monitor | CVE-2025-68049No exploit | WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerabilitybunny.net · bunny.net · CWE-862 | Medium6.3 | — | 0.2% | Jun 15, 2026 |
17Monitor | CVE-2025-14481No exploit | Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameteryoast · yoast seo – advanced seo with real-time guidance and built-in ai · CWE-862 | Medium4.3 | — | 0.3% | May 27, 2026 |
21Monitor | CVE-2026-39657No exploit | WordPress leadlovers forms plugin <= 1.0.2 - Broken Access Control vulnerabilityleadlovers · leadlovers forms · CWE-862 | Medium5.3 | — | 0.3% | Apr 8, 2026 |
39Monitor | CVE-2026-32523No exploit | WordPress WPJAM Basic plugin <= 6.9.2 - Arbitrary File Upload vulnerabilitydenishua · wpjam basic · CWE-434 | Critical9.9 | — | 0.5% | Mar 25, 2026 |
36Monitor | CVE-2026-25447No exploit | WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerabilityjonathan daggerhart · widget wrangler · CWE-94 | Critical9.1 | — | 0.5% | Mar 25, 2026 |
26Monitor | CVE-2026-24987No exploit | WordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerabilityactivity-log.com · wp system log · CWE-862 | Medium6.5 | — | 0.4% | Mar 25, 2026 |
30Monitor | CVE-2026-22448No exploit | WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerabilityflexcubed · pitchprint · CWE-22 | High7.5 | — | 0.6% | Mar 25, 2026 |
36Monitor | CVE-2026-27067No exploit | WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerabilitysyarif · mobile app editor · CWE-434 | Critical9.1 | — | 0.5% | Mar 19, 2026 |
21Monitor | CVE-2026-32410No exploit | WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerabilitywbw plugins · wbw currency switcher for woocommerce · CWE-862 | Medium5.3 | — | 0.3% | Mar 13, 2026 |
37Monitor | CVE-2026-24956No exploit | WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerabilityshahjada · download manager addons for elementor · CWE-89 | Critical9.3 | — | 0.2% | Feb 20, 2026 |
30Monitor | CVE-2026-24950No exploit | WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerabilitythemeplugs · authorsy · CWE-639 | High7.5 | — | 0.3% | Feb 20, 2026 |
30Monitor | CVE-2025-68834No exploit | WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerabilitysaiful islam · sync master sheet – product sync with google sheet for woocommerce · CWE-862 | High7.5 | — | 0.3% | Feb 20, 2026 |
30Monitor | CVE-2025-68051No exploit | WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerabilityshiprocket · shiprocket · CWE-639 | High7.5 | — | 0.3% | Feb 20, 2026 |
26Monitor | CVE-2025-68050No exploit | WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerabilityleadpages · leadpages · CWE-862 | Medium6.5 | — | 0.2% | Feb 20, 2026 |
30Monitor | CVE-2025-68048No exploit | WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerabilityxlplugins · nextmove lite · CWE-862 | High7.5 | — | 0.3% | Feb 20, 2026 |
29Monitor | CVE-2025-68043Proof of concept | WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerabilitylottiefiles · lottiefiles · CWE-862 | High7.3 | — | 0.6% | Feb 20, 2026 |
29Monitor | CVE-2025-68022No exploit | WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerabilitysoporteblue · plugin bluex for woocommerce · CWE-862 | High7.3 | — | 0.3% | Feb 20, 2026 |
26Monitor | CVE-2025-68021No exploit | WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerabilityconveythis · conveythis · CWE-862 | Medium6.5 | — | 0.3% | Feb 20, 2026 |
30Monitor | CVE-2025-67974No exploit | WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerabilitywp legal pages · wplegalpages · CWE-862 | High7.5 | — | 0.3% | Feb 20, 2026 |
26Monitor | CVE-2025-67969No exploit | WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerabilityknitpay · upi qr code payment gateway for woocommerce · CWE-862 | Medium6.5 | — | 0.3% | Feb 20, 2026 |
26Monitor | CVE-2026-23545No exploit | WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerabilityaruba.it dev · aruba hispeed cache · CWE-862 | Medium6.5 | — | 0.2% | Feb 19, 2026 |
17Monitor | CVE-2026-24947No exploit | WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerabilityla-studio · la-studio element kit for elementor · CWE-862 | Medium4.3 | — | 0.2% | Feb 3, 2026 |
23Monitor | CVE-2026-22388No exploit | WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerabilityimran emu · owl carousel wp · CWE-79 | Medium5.9 | — | 0.3% | Jan 22, 2026 |
30Monitor | CVE-2025-68882No exploit | WordPress Scalenut plugin <= 1.1.5 - Broken Access Control vulnerabilityscalenut · scalenut · CWE-862 | High7.5 | — | 0.3% | Jan 22, 2026 |
- CVE-2026-1529130Monitor
Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 1%themeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat formJul 10, 2026
- CVE-2025-6804925Monitor
WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%bunny.net · bunny.netJun 15, 2026
- CVE-2025-1448117Monitor
Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter
MediumCVSS 4.3No exploitEPSS 0%yoast · yoast seo – advanced seo with real-time guidance and built-in aiMay 27, 2026
- CVE-2026-3965721Monitor
WordPress leadlovers forms plugin <= 1.0.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%leadlovers · leadlovers formsApr 8, 2026
- CVE-2026-3252339Monitor
WordPress WPJAM Basic plugin <= 6.9.2 - Arbitrary File Upload vulnerability
CriticalCVSS 9.9No exploitEPSS 0%denishua · wpjam basicMar 25, 2026
- CVE-2026-2544736Monitor
WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.1No exploitEPSS 1%jonathan daggerhart · widget wranglerMar 25, 2026
- CVE-2026-2498726Monitor
WordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%activity-log.com · wp system logMar 25, 2026
- CVE-2026-2244830Monitor
WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerability
HighCVSS 7.5No exploitEPSS 1%flexcubed · pitchprintMar 25, 2026
- CVE-2026-2706736Monitor
WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerability
CriticalCVSS 9.1No exploitEPSS 0%syarif · mobile app editorMar 19, 2026
- CVE-2026-3241021Monitor
WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wbw plugins · wbw currency switcher for woocommerceMar 13, 2026
- CVE-2026-2495637Monitor
WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%shahjada · download manager addons for elementorFeb 20, 2026
- CVE-2026-2495030Monitor
WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerability
HighCVSS 7.5No exploitEPSS 0%themeplugs · authorsyFeb 20, 2026
- CVE-2025-6883430Monitor
WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%saiful islam · sync master sheet – product sync with google sheet for woocommerceFeb 20, 2026
- CVE-2025-6805130Monitor
WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerability
HighCVSS 7.5No exploitEPSS 0%shiprocket · shiprocketFeb 20, 2026
- CVE-2025-6805026Monitor
WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%leadpages · leadpagesFeb 20, 2026
- CVE-2025-6804830Monitor
WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%xlplugins · nextmove liteFeb 20, 2026
- CVE-2025-6804329Monitor
WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerability
HighCVSS 7.3Proof of conceptEPSS 1%lottiefiles · lottiefilesFeb 20, 2026
- CVE-2025-6802229Monitor
WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerability
HighCVSS 7.3No exploitEPSS 0%soporteblue · plugin bluex for woocommerceFeb 20, 2026
- CVE-2025-6802126Monitor
WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%conveythis · conveythisFeb 20, 2026
- CVE-2025-6797430Monitor
WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%wp legal pages · wplegalpagesFeb 20, 2026
- CVE-2025-6796926Monitor
WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%knitpay · upi qr code payment gateway for woocommerceFeb 20, 2026
- CVE-2026-2354526Monitor
WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%aruba.it dev · aruba hispeed cacheFeb 19, 2026
- CVE-2026-2494717Monitor
WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%la-studio · la-studio element kit for elementorFeb 3, 2026
- CVE-2026-2238823Monitor
WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.9No exploitEPSS 0%imran emu · owl carousel wpJan 22, 2026
- CVE-2025-6888230Monitor
WordPress Scalenut plugin <= 1.1.5 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%scalenut · scalenutJan 22, 2026