CatFather

CatFather is a security researcher credited with 39 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #156 of 3,515 contributors. The disclosure was published in 2024.

Their research concentrates on Cross-Site Scripting, which accounts for 21 of their findings (54%). Other recurring categories include Missing Authorization, Deserialization Of Untrusted Data. The average CVSS score across these disclosures is 5.9, peaking at 9.9. Severity breakdown: 2 critical and 2 high.

The most affected software includes SP Project & Document Manager (3), Church Admin (2), Contest Gallery (2), across 31 distinct plugins, themes and core versions in total.

31 of the 39 disclosed issues have a vendor fix, while 8 remain unpatched. The most severe finding, "SP Project & Document Manager <= 4.71 - Authenticated (Author+) SQL Injeciton", scores 9.9 out of 10.

2024
Critical
High
Medium
Low
Global Rank

#156

of 3,515 researchers

Vulns

39

Critical2
High2
Medium35
Low0
Affected Assets

31

31plugins
Avg CVSS

5.9

Average score of vulnerabilities

Researcher Submissions

39 records
2024-08-12 00:00CVE-2024-43252
8.1
High
CatFatherYes
2024-07-24 00:00CVE-2024-39631
6.1
Medium
CatFatherYes
2024-06-27 00:00CVE-2024-37271
6.4
Medium
CatFatherYes
2024-06-21 00:00CVE-2024-37224
4.3
Medium
CatFatherNo
2024-06-20 00:00CVE-2024-37204
4.3
Medium
CatFatherYes
2024-06-06 00:00CVE-2024-35723
4.3
Medium
CatFatherYes
2024-06-06 00:00CVE-2024-35694
6.1
Medium
CatFatherYes
2024-06-06 00:00CVE-2024-35701
6.4
Medium
CatFatherYes
2024-05-20 00:00CVE-2024-34801
6.4
Medium
CatFatherYes
2024-05-07 00:00CVE-2024-34574
5.4
Medium
CatFatherNo
Showing 1–10 of 39 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C