AlexHenry

AlexHenry is a security researcher credited with 19 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #273 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 14 findings.

Their research concentrates on Missing Authorization, which accounts for 6 of their findings (32%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 6.0, peaking at 8.8. Severity breakdown: 0 critical and 5 high.

The most affected software includes LearnPress (2), Ad Inserter (1), All-in-One WP Migration and Backup (1), across 18 distinct plugins, themes and core versions in total.

All 19 disclosed issues have since received a vendor fix. The most severe finding, "WP Editor <= 1.2.9.2 - Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor", scores 8.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#273

of 3,515 researchers

Vulns

19

Critical0
High5
Medium14
Low0
Affected Assets

18

18plugins
Avg CVSS

6.0

Average score of vulnerabilities

Researcher Submissions

19 records
2026-08-05 22:18CVE-2026-11983
5.3
Medium
AlexHenryYes
2026-06-30 16:02CVE-2026-12127
5.3
Medium
AlexHenryYes
2026-06-05 10:46CVE-2026-8976
4.3
Medium
AlexHenryYes
2026-05-28 18:57CVE-2026-6075
8.1
High
AlexHenryYes
2026-05-27 14:55CVE-2026-9228
4.3
Medium
AlexHenryYes
2026-05-04 16:06CVE-2026-4362
6.5
Medium
AlexHenryYes
2026-05-01 16:12CVE-2026-4658
6.4
Medium
AlexHenryYes
2026-04-30 00:00CVE-2026-3772
8.8
High
AlexHenryYes
2026-04-16 13:23CVE-2026-3488
6.5
Medium
AlexHenryYes
2026-03-30 15:35CVE-2026-4146
6.1
Medium
AlexHenryYes
Showing 1–10 of 19 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C