Alyudin Nafiie
Alyudin Nafiie is a security researcher credited with 21 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #238 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 13 findings.
Their research concentrates on Improper Privilege Management, which accounts for 14 of their findings (67%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism For Forgotten Password. The average CVSS score across these disclosures is 9.5, peaking at 9.8. Severity breakdown: 16 critical and 5 high.
The most affected software includes Invoice Generator (2), Lisfinity Core - Lisfinity Core plugin… (2), Real Spaces - WordPress Properties… (2), across 18 distinct plugins, themes and core versions in total.
13 of the 21 disclosed issues have a vendor fix, while 8 remain unpatched. The most severe finding, "WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action", scores 9.8 out of 10.
#238
of 3,515 researchers
21
18
9.5
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C