PPzzAArr
Patchstack Bug Bounty Program
20 credited records · 19 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
23Monitor | CVE-2026-27365No exploit | WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) vulnerabilitypublishpress · publishpress series · CWE-79 | Medium5.9 | — | 0.2% | Aug 18, 2026 |
21Monitor | CVE-2026-27329No exploit | WordPress YITH WooCommerce Wishlist plugin <= 4.12.0 - Insecure Direct Object References (IDOR) vulnerabilityyith · yith woocommerce wishlist · CWE-639 | Medium5.3 | — | 0.3% | May 7, 2026 |
26Monitor | CVE-2026-27046No exploit | WordPress StoreCustomizer plugin <= 2.6.3 - Broken Access Control vulnerabilitykaira · storecustomizer · CWE-862 | Medium6.5 | — | 0.3% | Mar 25, 2026 |
26Monitor | CVE-2026-25465No exploit | WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerabilitycodepeople · cp multi view event calendar · CWE-79 | Medium6.5 | — | 0.2% | Mar 25, 2026 |
30Monitor | CVE-2026-24372No exploit | WordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerabilitywp swings · subscriptions for woocommerce · CWE-290 | High7.5 | — | 0.5% | Mar 25, 2026 |
26Monitor | CVE-2026-23972No exploit | WordPress Booking and Rental Manager plugin <= 2.6.0 - Broken Access Control vulnerabilitymagepeopleteam · booking and rental manager · CWE-862 | Medium6.5 | — | 0.3% | Mar 25, 2026 |
17Monitor | CVE-2026-31919No exploit | WordPress Advanced Coupons for WooCommerce Coupons plugin <= 4.7.1 - Broken Access Control vulnerabilityjosh kohlbach · advanced coupons for woocommerce coupons · CWE-862 | Medium4.3 | — | 0.3% | Mar 13, 2026 |
23Monitor | CVE-2026-27344Proof of concept | WordPress inseri core plugin <= 1.0.5 - Broken Access Control vulnerabilityinseriswiss · inseri core · CWE-862 | Medium5.9 | — | 0.3% | Mar 5, 2026 |
30Monitor | CVE-2026-24385No exploit | WordPress Podlove Web Player plugin <= 5.9.1 - PHP Object Injection vulnerabilitygerritvanaaken · podlove web player · CWE-502 | High7.5 | — | 0.3% | Mar 5, 2026 |
26Monitor | CVE-2025-69343No exploit | WordPress Theater for WordPress plugin <= 0.19 - Cross Site Scripting (XSS) vulnerabilityjeroen schmit · theater for wordpress · CWE-79 | Medium6.5 | — | 0.2% | Mar 5, 2026 |
21Monitor | CVE-2026-27042No exploit | WordPress NotificationX plugin <= 3.2.1 - Broken Access Control vulnerabilitywpdeveloper · notificationx · CWE-862 | Medium5.3 | — | 0.3% | Feb 19, 2026 |
21Monitor | CVE-2026-24375No exploit | WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.4 - Broken Access Control vulnerabilitywp swings · ultimate gift cards for woocommerce · CWE-862 | Medium5.3 | — | 0.2% | Feb 19, 2026 |
26Monitor | CVE-2026-24988No exploit | WordPress The Events Calendar Shortcode & Block plugin <= 3.1.1 - Cross Site Scripting (XSS) vulnerabilitybrian hogg · the events calendar shortcode & block · CWE-79 | Medium6.5 | — | 0.1% | Feb 3, 2026 |
21Monitor | CVE-2026-24599No exploit | WordPress NextMove Lite plugin <= 2.23.0 - Insecure Direct Object References (IDOR) vulnerabilityxlplugins · nextmove lite · CWE-639 | Medium5.3 | — | 0.4% | Jan 23, 2026 |
21Monitor | CVE-2026-24366No exploit | WordPress YITH WooCommerce Request A Quote plugin <= 2.46.0 - Broken Access Control vulnerabilityyithemes · yith woocommerce request a quote · CWE-862 | Medium5.3 | — | 0.2% | Jan 22, 2026 |
21Monitor | CVE-2026-22461No exploit | WordPress CTX Feed plugin <= 6.6.18 - Broken Access Control vulnerabilitywebappick · ctx feed · CWE-862 | Medium5.3 | — | 0.4% | Jan 22, 2026 |
17Monitor | CVE-2025-69327No exploit | WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerabilitymagepeopleteam · car rental manager · CWE-862 | Medium4.3 | — | 0.3% | Jan 6, 2026 |
17Monitor | CVE-2025-67621No exploit | WordPress Eight Day Week Print Workflow plugin <= 1.2.5 - Sensitive Data Exposure vulnerability10up · eight day week print workflow · CWE-497 | Medium4.3 | — | 0.3% | Dec 24, 2025 |
19Monitor | CVE-2025-64253No exploit | WordPress Health Check & Troubleshooting plugin <= 1.7.1 - Path Traversal vulnerabilitywordpress.org · health check & troubleshooting · CWE-35 | Medium4.9 | — | 0.5% | Dec 16, 2025 |
21Monitor | CVE-2025-47444No exploit | WordPress FiboSearch plugin <= 1.32.1 - Broken Access Control vulnerabilitydamian góra · fibosearch · CWE-862 | Medium5.3 | — | 0.2% | Aug 12, 2025 |
- CVE-2026-2736523Monitor
WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.9No exploitEPSS 0%publishpress · publishpress seriesAug 18, 2026
- CVE-2026-2732921Monitor
WordPress YITH WooCommerce Wishlist plugin <= 4.12.0 - Insecure Direct Object References (IDOR) vulnerability
MediumCVSS 5.3No exploitEPSS 0%yith · yith woocommerce wishlistMay 7, 2026
- CVE-2026-2704626Monitor
WordPress StoreCustomizer plugin <= 2.6.3 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%kaira · storecustomizerMar 25, 2026
- CVE-2026-2546526Monitor
WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%codepeople · cp multi view event calendarMar 25, 2026
- CVE-2026-2437230Monitor
WordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerability
HighCVSS 7.5No exploitEPSS 0%wp swings · subscriptions for woocommerceMar 25, 2026
- CVE-2026-2397226Monitor
WordPress Booking and Rental Manager plugin <= 2.6.0 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%magepeopleteam · booking and rental managerMar 25, 2026
- CVE-2026-3191917Monitor
WordPress Advanced Coupons for WooCommerce Coupons plugin <= 4.7.1 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%josh kohlbach · advanced coupons for woocommerce couponsMar 13, 2026
- CVE-2026-2734423Monitor
WordPress inseri core plugin <= 1.0.5 - Broken Access Control vulnerability
MediumCVSS 5.9Proof of conceptEPSS 0%inseriswiss · inseri coreMar 5, 2026
- CVE-2026-2438530Monitor
WordPress Podlove Web Player plugin <= 5.9.1 - PHP Object Injection vulnerability
HighCVSS 7.5No exploitEPSS 0%gerritvanaaken · podlove web playerMar 5, 2026
- CVE-2025-6934326Monitor
WordPress Theater for WordPress plugin <= 0.19 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%jeroen schmit · theater for wordpressMar 5, 2026
- CVE-2026-2704221Monitor
WordPress NotificationX plugin <= 3.2.1 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wpdeveloper · notificationxFeb 19, 2026
- CVE-2026-2437521Monitor
WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.4 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wp swings · ultimate gift cards for woocommerceFeb 19, 2026
- CVE-2026-2498826Monitor
WordPress The Events Calendar Shortcode & Block plugin <= 3.1.1 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%brian hogg · the events calendar shortcode & blockFeb 3, 2026
- CVE-2026-2459921Monitor
WordPress NextMove Lite plugin <= 2.23.0 - Insecure Direct Object References (IDOR) vulnerability
MediumCVSS 5.3No exploitEPSS 0%xlplugins · nextmove liteJan 23, 2026
- CVE-2026-2436621Monitor
WordPress YITH WooCommerce Request A Quote plugin <= 2.46.0 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%yithemes · yith woocommerce request a quoteJan 22, 2026
- CVE-2026-2246121Monitor
WordPress CTX Feed plugin <= 6.6.18 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%webappick · ctx feedJan 22, 2026
- CVE-2025-6932717Monitor
WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%magepeopleteam · car rental managerJan 6, 2026
- CVE-2025-6762117Monitor
WordPress Eight Day Week Print Workflow plugin <= 1.2.5 - Sensitive Data Exposure vulnerability
MediumCVSS 4.3No exploitEPSS 0%10up · eight day week print workflowDec 24, 2025
- CVE-2025-6425319Monitor
WordPress Health Check & Troubleshooting plugin <= 1.7.1 - Path Traversal vulnerability
MediumCVSS 4.9No exploitEPSS 0%wordpress.org · health check & troubleshootingDec 16, 2025
- CVE-2025-4744421Monitor
WordPress FiboSearch plugin <= 1.32.1 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%damian góra · fibosearchAug 12, 2025