Skip to content
Noroxi

Webula

Patchstack Bug Bounty Program

16 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    rocketelements · split test for elementorApr 4, 2025

  • WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.9Proof of conceptEPSS 0%

    out the box · beam me up scottyApr 1, 2025

  • WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability

    HighCVSS 8.8Proof of conceptEPSS 1%

    squirrly · seo plugin by squirrly seoMar 27, 2025

  • WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    kendysond · payment forms for paystackMar 27, 2025

  • WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    tribulant software · newslettersMar 27, 2025

  • WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerability

    HighCVSS 7.6No exploitEPSS 0%

    publishpress · publishpress authorsMar 15, 2025

  • WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    ays-pro · poll makerFeb 25, 2025

  • WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    webilia inc. · vertex addons for elementorFeb 17, 2025

  • WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    sendpulse · sendpulse email marketing newsletterFeb 4, 2025

  • WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    shahjada · wpdm – premium packagesJan 24, 2025

  • WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 32%

    nks · email subscription popupJan 24, 2025

  • WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    storeapps · smart managerJan 21, 2025

  • WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability

    HighCVSS 7.2Proof of conceptEPSS 1%

    kkarpieszuk · wc price history for omnibusJan 9, 2025

  • WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    elextensions · elex woocommerce advanced bulk edit products, prices & attributesJan 7, 2025

  • WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1Proof of conceptEPSS 1%

    adrian tobey · groundhoggJan 7, 2025

  • WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    smackcoders inc., · wp ultimate exporterJan 7, 2025