D01EXPLOIT OFFICIAL

D01EXPLOIT OFFICIAL is a security researcher credited with 11 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #412 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 8 findings.

Their research concentrates on Missing Authorization, which accounts for 6 of their findings (55%). Other recurring categories include Server-Side Request Forgery (SSRF), Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 5.7, peaking at 9.8. Severity breakdown: 1 critical and 1 high.

The most affected software includes Printcart Store (2), Simple User Capabilities (2), AppPresser (1), across 9 distinct plugins, themes and core versions in total.

7 of the 11 disclosed issues have a vendor fix, while 4 remain unpatched. The most severe finding, "Simple User Capabilities <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#412

of 3,515 researchers

Vulns

11

Critical1
High1
Medium9
Low0
Affected Assets

9

9plugins
Avg CVSS

5.7

Average score of vulnerabilities

Researcher Submissions

11 records
2026-09-04 00:00CVE-2025-15691
5.3
Medium
D01EXPLOIT OFFICIALYes
2026-07-06 00:00CVE-2025-15662
7.5
High
D01EXPLOIT OFFICIALYes
2026-06-04 00:00CVE-2025-10268
5.3
Medium
D01EXPLOIT OFFICIALNo
2025-12-11 14:26CVE-2025-13408
4.3
Medium
D01EXPLOIT OFFICIALYes
2025-11-03 15:33CVE-2025-12158
9.8
Critical
D01EXPLOIT OFFICIALNo
2025-11-03 15:33CVE-2025-12157
5.3
Medium
D01EXPLOIT OFFICIALNo
2025-10-29 00:00CVE-2025-11881
5.3
Medium
D01EXPLOIT OFFICIALYes
2025-10-14 20:02CVE-2025-10486
5.3
Medium
D01EXPLOIT OFFICIALYes
2025-10-02 21:55CVE-2025-10212
5.3
Medium
D01EXPLOIT OFFICIALNo
2025-09-30 00:00CVE-2025-10735
4.0
Medium
D01EXPLOIT OFFICIALYes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C