Alyudin Nafiie

Alyudin Nafiie is a security researcher credited with 21 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #238 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 13 findings.

Their research concentrates on Improper Privilege Management, which accounts for 14 of their findings (67%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism For Forgotten Password. The average CVSS score across these disclosures is 9.5, peaking at 9.8. Severity breakdown: 16 critical and 5 high.

The most affected software includes Invoice Generator (2), Lisfinity Core - Lisfinity Core plugin… (2), Real Spaces - WordPress Properties… (2), across 18 distinct plugins, themes and core versions in total.

13 of the 21 disclosed issues have a vendor fix, while 8 remain unpatched. The most severe finding, "WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#238

of 3,515 researchers

Vulns

21

Critical16
High5
Medium0
Low0
Affected Assets

18

17plugins1theme
Avg CVSS

9.5

Average score of vulnerabilities

Researcher Submissions

21 records
2026-07-07 16:31CVE-2026-12153
9.8
Critical
Alyudin NafiieNo
2026-06-26 16:05CVE-2026-12415
9.8
Critical
Alyudin NafiieNo
2026-06-23 16:37CVE-2026-12416
9.8
Critical
Alyudin NafiieNo
2026-06-23 16:37CVE-2026-12417
9.8
Critical
Alyudin NafiieNo
2026-02-18 18:11CVE-2026-1994
9.8
Critical
Alyudin NafiieYes
2026-02-18 15:49CVE-2025-13563
9.8
Critical
Alyudin NafiieYes
2026-02-18 15:10CVE-2025-12882
9.8
Critical
Alyudin NafiieNo
2026-02-13 20:06CVE-2025-8572
9.8
Critical
Alyudin NafiieYes
2025-11-24 15:49CVE-2025-13559
9.8
Critical
Alyudin NafiieNo
2025-10-31 18:22CVE-2025-8900
9.8
Critical
Alyudin NafiieYes
Showing 1–10 of 21 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C