ch4r0n

ch4r0n is a security researcher credited with 104 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #71 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 103 findings.

Their research concentrates on Missing Authorization, which accounts for 51 of their findings (49%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection. The average CVSS score across these disclosures is 5.8, peaking at 9.8. Severity breakdown: 5 critical and 18 high.

The most affected software includes Spreadsheet Price Changer… (4), URL Shortener Plugin For WordPress (4), Amazon Products to WooCommerce (2), across 90 distinct plugins, themes and core versions in total.

48 of the 104 disclosed issues have a vendor fix, while 56 remain unpatched. The most severe finding, "The E-Commerce ERP <= 2.1.1.3 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#71

of 3,515 researchers

Vulns

104

Critical5
High18
Medium80
Low1
Affected Assets

90

90plugins
Avg CVSS

5.8

Average score of vulnerabilities

Researcher Submissions

104 records
2026-04-08 00:00CVE-2026-39480
5.3
Medium
ch4r0nYes
2025-11-26 16:26CVE-2025-7820
7.5
High
ch4r0nYes
2025-10-29 00:00CVE-2025-57931
4.3
Medium
ch4r0nYes
2025-10-02 22:14CVE-2025-7825
6.3
Medium
ch4r0nNo
2025-09-22 00:00CVE-2025-57939
5.4
Medium
ch4r0nNo
2025-09-09 17:41CVE-2025-7826
6.5
Medium
ch4r0nNo
2025-08-27 00:00CVE-2025-58201
5.3
Medium
ch4r0nYes
2025-08-26 00:00CVE-2025-49403
7.5
High
ch4r0nNo
2025-08-25 00:00CVE-2025-4956
4.3
Medium
ch4r0nNo
2025-08-22 15:52CVE-2025-7828
4.3
Medium
ch4r0nNo
Showing 1–10 of 104 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C