afnaan

afnaan is a security researcher credited with 46 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #131 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 44 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 44 of their findings (96%). Other recurring categories include Improper Neutralization Of Script-Related HTML Tags In A Web Page (Basic XSS). The average CVSS score across these disclosures is 4.3, peaking at 5.4.

The most affected software includes Amazon affiliate lite Plugin (2), Add Google Social Profiles… (1), AJAX Report Comments (1), across 45 distinct plugins, themes and core versions in total.

5 of the 46 disclosed issues have a vendor fix, while 41 remain unpatched.

20252026
Critical
High
Medium
Low
Global Rank

#131

of 3,515 researchers

Vulns

46

Critical0
High0
Medium46
Low0
Affected Assets

45

45plugins
Avg CVSS

4.3

Average score of vulnerabilities

Researcher Submissions

46 records
2026-06-29 16:17CVE-2026-8944
4.3
Medium
afnaanNo
2026-06-08 15:06CVE-2026-8940
4.3
Medium
afnaanNo
2026-06-08 15:05CVE-2026-8904
4.3
Medium
afnaanNo
2026-06-08 15:05CVE-2026-8902
4.3
Medium
afnaanNo
2026-06-01 19:43CVE-2026-9599
4.3
Medium
afnaanNo
2026-05-26 18:57CVE-2026-8942
4.3
Medium
afnaanNo
2026-05-26 17:23CVE-2026-8943
4.3
Medium
afnaanNo
2026-05-26 17:23CVE-2026-8941
4.3
Medium
afnaanNo
2026-05-26 17:23CVE-2026-8939
4.3
Medium
afnaanNo
2026-05-26 17:23CVE-2026-8938
4.3
Medium
afnaanNo
Showing 1–10 of 46 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C