Skip to content
Noroxi

NumeX

Patchstack Bug Bounty Program

51 credited records · 50 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    HighCVSS 7.5No exploitEPSS 1%

    themeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat formJul 10, 2026

  • WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    bunny.net · bunny.netJun 15, 2026

  • Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter

    MediumCVSS 4.3No exploitEPSS 0%

    yoast · yoast seo – advanced seo with real-time guidance and built-in aiMay 27, 2026

  • WordPress leadlovers forms plugin <= 1.0.2 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    leadlovers · leadlovers formsApr 8, 2026

  • WordPress WPJAM Basic plugin <= 6.9.2 - Arbitrary File Upload vulnerability

    CriticalCVSS 9.9No exploitEPSS 0%

    denishua · wpjam basicMar 25, 2026

  • WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.1No exploitEPSS 1%

    jonathan daggerhart · widget wranglerMar 25, 2026

  • WordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    activity-log.com · wp system logMar 25, 2026

  • WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    flexcubed · pitchprintMar 25, 2026

  • WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerability

    CriticalCVSS 9.1No exploitEPSS 0%

    syarif · mobile app editorMar 19, 2026

  • WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    wbw plugins · wbw currency switcher for woocommerceMar 13, 2026

  • WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    shahjada · download manager addons for elementorFeb 20, 2026

  • WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    themeplugs · authorsyFeb 20, 2026

  • WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    saiful islam · sync master sheet – product sync with google sheet for woocommerceFeb 20, 2026

  • WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    shiprocket · shiprocketFeb 20, 2026

  • WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    leadpages · leadpagesFeb 20, 2026

  • WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    xlplugins · nextmove liteFeb 20, 2026

  • WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerability

    HighCVSS 7.3Proof of conceptEPSS 1%

    lottiefiles · lottiefilesFeb 20, 2026

  • WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerability

    HighCVSS 7.3No exploitEPSS 0%

    soporteblue · plugin bluex for woocommerceFeb 20, 2026

  • WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    conveythis · conveythisFeb 20, 2026

  • WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    wp legal pages · wplegalpagesFeb 20, 2026

  • WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    knitpay · upi qr code payment gateway for woocommerceFeb 20, 2026

  • WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    aruba.it dev · aruba hispeed cacheFeb 19, 2026

  • WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    la-studio · la-studio element kit for elementorFeb 3, 2026

  • WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    imran emu · owl carousel wpJan 22, 2026

  • WordPress Scalenut plugin <= 1.1.5 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    scalenut · scalenutJan 22, 2026