Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Saad Iqbal — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting Saad Iqbal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Saad Iqbal is a security researcher with thirty-seven assigned CVEs, primarily focusing on vulnerability discovery within widely used software ecosystems. His work predominantly targets remote code execution, cross-site scripting, and privilege escalation flaws, often affecting enterprise applications and open-source libraries. Iqbal’s contributions highlight systemic weaknesses in input validation and access control mechanisms, demonstrating a consistent pattern of identifying critical logic errors that allow unauthorized system access. Notable incidents include disclosures that forced immediate patches for high-profile platforms, underscoring the severity of the identified defects. His research emphasizes the importance of rigorous code auditing and secure development practices. By documenting these vulnerabilities, Iqbal aids developers in strengthening their security postures, reducing the attack surface for potential adversaries, and promoting broader industry awareness regarding common exploitation vectors in modern software architectures.

CVE ID Title CVSS Severity Published
CVE-2026-84762 WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability — WP EasyPay CWE-472 5.3 Medium 2026-09-03
CVE-2026-73345 WordPress License Manager for WooCommerce plugin <= 3.0.18 - SQL Injection vulnerability — License Manager for WooCommerce CWE-89 7.1 High 2026-08-18
CVE-2026-66425 WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability — Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder CWE-288 6.5 Medium 2026-08-06
CVE-2026-57808 WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability — WP EasyPay CWE-862 6.5 Medium 2026-07-23
CVE-2026-57810 WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability — APIExperts Square for WooCommerce CWE-89 8.5 High 2026-07-13
CVE-2026-61968 WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability — myCred CWE-862 5.4 Medium 2026-07-13
CVE-2026-61958 WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability — License Manager for WooCommerce CWE-862 5.4 Medium 2026-07-13
CVE-2026-54848 WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data Exposure vulnerability — APIExperts Square for WooCommerce CWE-201 8.3 High 2026-06-25
CVE-2026-56024 WordPress WP EasyPay plugin <= 4.5.0 - Cross Site Request Forgery (CSRF) vulnerability — WP EasyPay CWE-352 6.5 Medium 2026-06-18
CVE-2026-45215 WordPress WP EasyPay plugin <= 4.3.0 - Sensitive Data Exposure vulnerability — WP EasyPay CWE-201 5.3 Medium 2026-05-12
CVE-2026-45211 WordPress APIExperts Square for WooCommerce plugin <= 4.7.1 - SQL Injection vulnerability — APIExperts Square for WooCommerce CWE-89 8.5 High 2026-05-12
CVE-2026-25390 WordPress New User Approve plugin <= 3.2.3 - Broken Access Control vulnerability — New User Approve CWE-862 6.5 Medium 2026-03-25
CVE-2026-25001 WordPress Post Snippets plugin <= 4.0.12 - Remote Code Execution (RCE) vulnerability — Post Snippets CWE-94 8.5 High 2026-03-25
CVE-2026-32587 WordPress WP EasyPay plugin <= 4.2.11 - Broken Access Control vulnerability — WP EasyPay CWE-862 5.4 Medium 2026-03-16
CVE-2025-69063 WordPress New User Approve plugin <= 3.2.0 - Broken Access Control vulnerability — New User Approve CWE-862 8.6 High 2026-02-20
CVE-2026-27440 WordPress myCred plugin <= 2.9.7.6 - Cross Site Scripting (XSS) vulnerability — myCred CWE-79 6.5 Medium 2026-02-19
CVE-2026-24951 WordPress myCred plugin <= 2.9.7.3 - Broken Access Control vulnerability — myCred CWE-862 4.3 Medium 2026-02-03
CVE-2025-68881 WordPress AppExperts plugin <= 1.4.5 - SQL Injection vulnerability — AppExperts CWE-89 8.5 High 2026-01-22
CVE-2025-63040 WordPress Post Snippets plugin <= 4.0.11 - Cross Site Request Forgery (CSRF) vulnerability — Post Snippets CWE-352 4.3 Medium 2025-12-31
CVE-2025-68080 WordPress User Avatar - Reloaded plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability — User Avatar - Reloaded CWE-79 6.5 Medium 2025-12-16
CVE-2025-63030 WordPress New User Approve plugin <= 3.2.3 - Cross Site Request Forgery (CSRF) vulnerability — New User Approve CWE-352 7.1 High 2025-12-09
CVE-2025-67563 WordPress Post SMTP plugin <= 3.6.1 - Broken Access Control vulnerability — Post SMTP CWE-862 5.3 Medium 2025-12-09
CVE-2025-67471 WordPress Quick Contact Form plugin <= 8.2.5 - Cross Site Request Forgery (CSRF) vulnerability — Quick Contact Form CWE-352 4.3 Medium 2025-12-09
CVE-2025-58595 WordPress All In One Login plugin <= 2.0.8 - Bypass Vulnerability vulnerability — All In One Login CWE-290 5.3 Medium 2025-11-06
CVE-2025-53218 WordPress AppExperts plugin <= 1.4.5 - Sensitive Data Exposure vulnerability — AppExperts CWE-201 5.8 Medium 2025-10-22
CVE-2025-58788 WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability — License Manager for WooCommerce CWE-89 7.6 High 2025-09-05
CVE-2025-48142 WordPress Bookify <= 1.0.9 - Privilege Escalation Vulnerability — Bookify CWE-266 8.8 High 2025-08-20
CVE-2025-54668 WordPress myCred plugin <= 2.9.4.3 - Cross Site Scripting (XSS) Vulnerability — myCred CWE-79 6.5 Medium 2025-08-14
CVE-2025-54667 WordPress myCred plugin <= 2.9.4.3 - Race Condition Vulnerability — myCred CWE-367 5.3 Medium 2025-08-14
CVE-2025-24000 WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability — Post SMTP CWE-288 8.8 High 2025-08-07

This page lists every published CVE security advisory associated with Saad Iqbal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.