Dimas Maulana

Dimas Maulana is a security researcher credited with 171 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #45 of 3,515 contributors. Their disclosures were published between 2023 and 2026. The most productive year was 2024, with 110 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 116 of their findings (68%). Other recurring categories include PHP Remote File Inclusion, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 6.8, peaking at 9.8. Severity breakdown: 31 critical and 17 high.

The most affected software includes Convert Post Types (2), Grab & Save (2), postMash (2), across 167 distinct plugins, themes and core versions in total.

86 of the 171 disclosed issues have a vendor fix, while 85 remain unpatched. The most severe finding, "License For Envato <= 1.0.0 - Unauthenticated Local File Inclusion", scores 9.8 out of 10.

2023202420252026
Critical
High
Medium
Low
Global Rank

#45

of 3,515 researchers

Vulns

171

Critical31
High17
Medium123
Low0
Affected Assets

167

161plugins6themes
Avg CVSS

6.8

Average score of vulnerabilities

Researcher Submissions

171 records
2026-03-11 13:35CVE-2026-3657
7.5
High
Dimas MaulanaYes
2025-07-25 00:00CVE-2025-48293
8.1
High
Dimas MaulanaYes
2025-04-21 00:00CVE-2025-39399
9.8
Critical
Dimas MaulanaYes
2025-04-21 00:00CVE-2025-39397
6.1
Medium
Dimas MaulanaNo
2025-04-21 00:00CVE-2025-39391
9.8
Critical
Dimas MaulanaYes
2025-04-21 00:00CVE-2025-32921
9.8
Critical
Dimas MaulanaNo
2025-04-21 00:00CVE-2025-39383
9.8
Critical
Dimas MaulanaNo
2025-04-21 00:00CVE-2025-39384
9.8
Critical
Dimas MaulanaNo
2025-04-21 00:00CVE-2025-39382
6.1
Medium
Dimas MaulanaNo
2025-04-21 00:00CVE-2025-39359
9.8
Critical
Dimas MaulanaNo
Showing 1–10 of 171 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C