CVE Archive
Bug bounty // WordPress
These are the CVEs I've got from bug bounty work on WordPress plugins. I report through Wordfence and Patchstack. Once the vendor ships a fix, the advisory goes public, the CVE is published and the bounty is paid.
Most of what I find is in access control and input handling: REST routes or AJAX actions without proper permission checks, SQL built from user input, and stored XSS. I mostly look for bugs that work without logging in. The highest one here is an unauthenticated RCE in Easy Invoice (CVSS 10.0).
22CVEs assigned
4Critical (9.0+)
12No login needed
#244Wordfence all time
Critical · 4 High · 12 Medium · 6
0x01
Process
The process is the same for every one of them.
FindRead the plugin code and look at what an outside user can reach.
PoCConfirm it on a local WordPress install.
ReportSend it to the bounty program with the code path and impact.
PatchThey verify it and contact the vendor.
CVE + bountyAdvisory and CVE published, bounty paid.
0x02
The archive
CVSSCVEAffected pluginTypePublished
9.3 CVE-2026-61950 TrueBooker Appointment Booking and Scheduler System <= 1.2.3 Unauthenticated SQL Injection 2026-07-16
8.5 CVE-2026-57765 Shopping Cart & eCommerce Store <= 5.9.1 Authenticated (Contributor+) SQL Injection 2026-07-02
7.5 CVE-2026-54824 Quads Ads Manager for Google AdSense <= 3.0.3 Unauthenticated Information Exposure 2026-06-17
7.5 CVE-2026-54828 Motors Car Dealership & Classified Listings <= 1.4.109 Missing Authorization 2026-06-17
7.1 CVE-2026-27536 MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 Unauthenticated Stored Cross-Site Scripting 2026-08-11
7.1 CVE-2026-57403 GD Security Headers <= 1.8 Unauthenticated Stored Cross-Site Scripting 2026-07-08
7.1 CVE-2026-57337 Landing Page Builder <= 1.5.3.5 Unauthenticated Stored Cross-Site Scripting 2026-06-29
6.5 CVE-2026-78536 Robokassa payment gateway for WooCommerce <= 1.8.9 Missing Authorization 2026-09-09
6.5 CVE-2026-81787 IMPress for IDX Broker <= 3.3.0 Unauthenticated Unauthorized Lead and Search Manipulation 2026-09-08
6.5 CVE-2026-56050 PPOM Product Addons & Custom Fields for WooCommerce <= 33.0.18 Missing Authorization 2026-06-25
0x03