ChamlaVic

ChamlaVic is a security researcher credited with 15 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #335 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 10 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 7 of their findings (47%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 5.0, peaking at 6.4.

The most affected software includes Alchemist Ajax Upload (1), Animated Pixel Marquee Creator (1), Crush.pics Image Optimizer (1), across 15 distinct plugins, themes and core versions in total.

4 of the 15 disclosed issues have a vendor fix, while 11 remain unpatched.

20252026
Critical
High
Medium
Low
Global Rank

#335

of 3,515 researchers

Vulns

15

Critical0
High0
Medium15
Low0
Affected Assets

15

15plugins
Avg CVSS

5.0

Average score of vulnerabilities

Researcher Submissions

15 records
2026-01-23 19:18CVE-2025-14629
5.3
Medium
ChamlaVicNo
2026-01-13 16:49CVE-2025-14482
4.3
Medium
ChamlaVicNo
2026-01-13 16:47CVE-2025-13627
4.4
Medium
ChamlaVicNo
2026-01-06 20:47CVE-2025-14053
6.4
Medium
ChamlaVicNo
2026-01-06 20:28CVE-2025-13667
6.4
Medium
ChamlaVicNo
2025-12-19 15:02CVE-2025-14633
5.3
Medium
ChamlaVicNo
2025-12-12 14:51CVE-2025-14050
4.9
Medium
ChamlaVicYes
2025-12-12 14:34CVE-2025-14454
4.3
Medium
ChamlaVicYes
2025-12-11 14:33CVE-2025-13971
4.4
Medium
ChamlaVicNo
2025-12-11 14:29CVE-2025-14035
4.4
Medium
ChamlaVicNo
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C