AlexHenry
AlexHenry is a security researcher credited with 19 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #273 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 14 findings.
Their research concentrates on Missing Authorization, which accounts for 6 of their findings (32%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 6.0, peaking at 8.8. Severity breakdown: 0 critical and 5 high.
The most affected software includes LearnPress (2), Ad Inserter (1), All-in-One WP Migration and Backup (1), across 18 distinct plugins, themes and core versions in total.
All 19 disclosed issues have since received a vendor fix. The most severe finding, "WP Editor <= 1.2.9.2 - Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor", scores 8.8 out of 10.
#273
of 3,515 researchers
19
18
6.0
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C