CVEs
Vulnerabilities I reported, with public advisories, affected versions and fixes. Related research is linked where available.
CVE-2026-96837
CVSS 8.8 · HighContributor remote code execution
↓ 11,049,982 WordPress downloads
Including updates ·
- Affected
- Through 3.2.0
- Fixed in
- 3.2.1
CVE-2026-94504
CVSS 7.2 · HighUnauthenticated stored cross-site scripting
↓ 63,819,545 WordPress downloads
Including updates ·
- Affected
- Through 3.15.3
- Fixed in
- 3.15.4
CVE-2026-81180
CVSS 8.8 · HighAuthenticated remote code execution
- Affected
- Through 2026.55 (vendor advisory)
- Fixed in
- 2026.61 (2026.58 provides a partial mitigation)
CVE-2026-81179
CVSS 8.1 · HighHost header injection / account takeover
- Affected
- Through 2026.55 (vendor advisory)
- Fixed in
- 2026.58