d.v4n_s3c

d.v4n_s3c is a security researcher credited with 15 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #324 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Improper Privilege Management, which accounts for 8 of their findings (53%). Other recurring categories include SQL Injection, Cross-Site Scripting. The average CVSS score across these disclosures is 8.4, peaking at 9.8. Severity breakdown: 5 critical and 7 high.

The most affected software includes Appointment Booking Plugin (2), Abandoned Cart Pro for WooCommerce (1), ACPT (Premium) (1), across 14 distinct plugins, themes and core versions in total.

All 15 disclosed issues have since received a vendor fix. The most severe finding, "ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#324

of 3,515 researchers

Vulns

15

Critical5
High7
Medium3
Low0
Affected Assets

14

13plugins1theme
Avg CVSS

8.4

Average score of vulnerabilities

Researcher Submissions

15 records
2026-09-04 00:00CVE-2026-81543
8.8
High
d.v4n_s3cYes
2026-09-03 18:24CVE-2026-15354
9.8
Critical
d.v4n_s3cYes
2026-09-01 00:00CVE-2026-9055
9.8
Critical
d.v4n_s3cYes
2026-08-31 21:31CVE-2026-18550
9.8
Critical
d.v4n_s3cYes
2026-08-31 21:00CVE-2026-15101
6.4
Medium
d.v4n_s3cYes
2026-08-28 00:00CVE-2026-14494
9.8
Critical
d.v4n_s3cYes
2026-08-11 06:12CVE-2026-15426
8.8
High
d.v4n_s3cYes
2026-08-07 18:30CVE-2026-14526
9.8
Critical
d.v4n_s3cYes
2026-06-30 21:30CVE-2026-13228
8.8
High
d.v4n_s3cYes
2026-06-30 15:24CVE-2026-12110
6.5
Medium
d.v4n_s3cYes
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C