cydave
cydave is a security researcher credited with 89 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #76 of 3,515 contributors. Their disclosures were published between 2022 and 2023. The most productive year was 2022, with 84 findings.
Their research concentrates on SQL Injection, which accounts for 43 of their findings (48%). Other recurring categories include Cross-Site Scripting, Unrestricted Upload Of File With Dangerous Type. The average CVSS score across these disclosures is 8.3, peaking at 9.8. Severity breakdown: 46 critical and 14 high.
The most affected software includes Awin Data Feed (2), BadgeOS (2), 3D Product configurator for WooCommerce (1), across 87 distinct plugins, themes and core versions in total.
72 of the 89 disclosed issues have a vendor fix, while 17 remain unpatched. The most severe finding, "Bitcoin / AltCoin Payment Gateway for WooCommerce <= 1.7.2 - Unauthenticated SQL Injection", scores 9.8 out of 10.
#76
of 3,515 researchers
89
87
8.3
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C