CVE Archive

CVE Archive

Bug bounty // WordPress

These are the CVEs I've got from bug bounty work on WordPress plugins. I report through Wordfence and Patchstack. Once the vendor ships a fix, the advisory goes public, the CVE is published and the bounty is paid.

Most of what I find is in access control and input handling: REST routes or AJAX actions without proper permission checks, SQL built from user input, and stored XSS. I mostly look for bugs that work without logging in. The highest one here is an unauthenticated RCE in Easy Invoice (CVSS 10.0).

22CVEs assigned
4Critical (9.0+)
12No login needed
#244Wordfence all time
Critical · 4 High · 12 Medium · 6
0x01

Process

The process is the same for every one of them.

FindRead the plugin code and look at what an outside user can reach.
PoCConfirm it on a local WordPress install.
ReportSend it to the bounty program with the code path and impact.
PatchThey verify it and contact the vendor.
CVE + bountyAdvisory and CVE published, bounty paid.
0x02

The archive

CVSSCVEAffected pluginTypePublished
10.0 CVE-2026-48836 Easy Invoice <= 2.1.19 Unauthenticated Remote Code Execution 2026-06-01
9.3 CVE-2026-61950 TrueBooker Appointment Booking and Scheduler System <= 1.2.3 Unauthenticated SQL Injection 2026-07-16
9.3 CVE-2026-57683 WP Fast Total Search <= 1.80.280 Unauthenticated SQL Injection 2026-06-29
9.3 CVE-2026-49776 GPTranslate <= 2.32.6 Unauthenticated SQL Injection 2026-06-04
8.8 CVE-2026-65542 Super Socializer <= 7.14.5 Missing Authorization 2026-07-28
8.5 CVE-2026-57765 Shopping Cart & eCommerce Store <= 5.9.1 Authenticated (Contributor+) SQL Injection 2026-07-02
7.5 CVE-2026-32481 Ezoic <= 2.22.11 Authentication Bypass 2026-08-14
7.5 CVE-2026-54824 Quads Ads Manager for Google AdSense <= 3.0.3 Unauthenticated Information Exposure 2026-06-17
7.5 CVE-2026-54828 Motors Car Dealership & Classified Listings <= 1.4.109 Missing Authorization 2026-06-17
7.1 CVE-2026-27536 MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 Unauthenticated Stored Cross-Site Scripting 2026-08-11
7.1 CVE-2026-57388 Hydra Booking <= 1.1.44 Unauthenticated Stored Cross-Site Scripting 2026-07-08
7.1 CVE-2026-57403 GD Security Headers <= 1.8 Unauthenticated Stored Cross-Site Scripting 2026-07-08
7.1 CVE-2026-57405 Open Shop theme <= 1.7.1 Missing Authorization 2026-07-08
7.1 CVE-2026-57362 WPBot AI ChatBot <= 8.3.2 Reflected Cross-Site Scripting 2026-07-01
7.1 CVE-2026-57337 Landing Page Builder <= 1.5.3.5 Unauthenticated Stored Cross-Site Scripting 2026-06-29
7.1 CVE-2026-42729 Property Hive <= 2.2.2 Unauthenticated Stored Cross-Site Scripting 2026-05-23
6.5 CVE-2026-78536 Robokassa payment gateway for WooCommerce <= 1.8.9 Missing Authorization 2026-09-09
6.5 CVE-2026-81787 IMPress for IDX Broker <= 3.3.0 Unauthenticated Unauthorized Lead and Search Manipulation 2026-09-08
6.5 CVE-2026-57375 MStore API <= 4.18.4 Missing Authorization 2026-07-07
6.5 CVE-2026-57340 Japanized for WooCommerce <= 2.9.12 Missing Authorization 2026-06-29
6.5 CVE-2026-56050 PPOM Product Addons & Custom Fields for WooCommerce <= 33.0.18 Missing Authorization 2026-06-25
6.3 CVE-2026-81788 IMPress for IDX Broker <= 3.3.0 Missing Authorization 2026-09-08
0x03

Where I report