ch4r0n
ch4r0n is a security researcher credited with 104 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #71 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 103 findings.
Their research concentrates on Missing Authorization, which accounts for 51 of their findings (49%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection. The average CVSS score across these disclosures is 5.8, peaking at 9.8. Severity breakdown: 5 critical and 18 high.
The most affected software includes Spreadsheet Price Changer… (4), URL Shortener Plugin For WordPress (4), Amazon Products to WooCommerce (2), across 90 distinct plugins, themes and core versions in total.
48 of the 104 disclosed issues have a vendor fix, while 56 remain unpatched. The most severe finding, "The E-Commerce ERP <= 2.1.1.3 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.
#71
of 3,515 researchers
104
90
5.8
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C