Skip to content
Noroxi

Roll

Patchstack Bug Bounty Program

4 credited records · 4 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    villatheme · product variations swatches for woocommerceSep 3, 2026

  • WordPress Paid Memberships Pro - Add Member From Admin plugin <= 0.7.2 - Cross Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    stranger studios · paid memberships pro - add member from adminJun 26, 2026

  • WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability

    HighCVSS 8.3No exploitEPSS 0%

    bplugins · mailchimp blockJun 26, 2026

  • WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    pluginus.net · mdtfJun 25, 2026