Bonds
Bonds is a security researcher credited with 465 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #13 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 278 findings.
Their research concentrates on PHP Remote File Inclusion, which accounts for 253 of their findings (54%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data. The average CVSS score across these disclosures is 7.7, peaking at 9.8. Severity breakdown: 65 critical and 292 high.
The most affected software includes RT-Theme 18 Responsive WordPress Theme (6), ARPrice - WordPress Pricing Table Plugin (5), Eagle Booking (4), across 388 distinct plugins, themes and core versions in total.
144 of the 465 disclosed issues have a vendor fix, while 321 remain unpatched. The most severe finding, "Type Hub <= 2.0.6 - Unauthenticated Arbitrary File Upload", scores 9.8 out of 10.
#13
of 3,515 researchers
465
483
7.7
Average score of vulnerabilities
Researcher Submissions
Showing the 250 most recent of 465 records. Every record has its own page and is listed in the sitemap.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C