dayea song

dayea song is a security researcher credited with 35 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #170 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 27 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 26 of their findings (74%). Other recurring categories include Cross-Site Scripting, Missing Authorization. The average CVSS score across these disclosures is 4.9, peaking at 7.5. Severity breakdown: 0 critical and 1 high.

The most affected software includes Anber Elementor Addon (2), Popover Windows (2), Simple Theme Changer (2), across 32 distinct plugins, themes and core versions in total.

2 of the 35 disclosed issues have a vendor fix, while 33 remain unpatched.

20252026
Critical
High
Medium
Low
Global Rank

#170

of 3,515 researchers

Vulns

35

Critical0
High1
Medium34
Low0
Affected Assets

32

32plugins
Avg CVSS

4.9

Average score of vulnerabilities

Researcher Submissions

35 records
2026-02-18 15:38CVE-2025-13413
4.3
Medium
dayea songNo
2026-02-18 15:38CVE-2025-13438
4.3
Medium
dayea songNo
2026-01-13 17:31CVE-2025-15376
4.3
Medium
dayea songNo
2026-01-13 17:22CVE-2025-15377
4.3
Medium
dayea songNo
2026-01-13 17:16CVE-2025-14389
4.3
Medium
dayea songNo
2026-01-06 20:30CVE-2025-13990
4.3
Medium
dayea songNo
2026-01-06 19:40CVE-2025-13519
6.1
Medium
dayea songNo
2026-01-06 19:39CVE-2025-13527
4.3
Medium
dayea songNo
2025-12-20 14:22CVE-2025-13361
4.3
Medium
dayea songYes
2025-12-12 16:09CVE-2025-14394
4.3
Medium
dayea songNo
Showing 1–10 of 35 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C