Eddie Zhang (Project Black)

Eddie Zhang (Project Black) is a security researcher credited with 11 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #388 of 3,515 contributors. The disclosure was published in 2024.

Their research concentrates on SQL Injection, which accounts for 7 of their findings (64%). Other recurring categories include PHP Remote File Inclusion, Cross-Site Scripting. The average CVSS score across these disclosures is 9.6, peaking at 10.0. Severity breakdown: 10 critical and 0 high.

The most affected software includes CZ Loan Management (1), Grow by Tradedoubler (1), News Element Elementor Blog Magazine (1), across 11 distinct plugins, themes and core versions in total.

8 of the 11 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "TrueBooker <= 1.0.3 - Unauthenticated SQL Injection", scores 10.0 out of 10.

2024
Critical
High
Medium
Low
Global Rank

#388

of 3,515 researchers

Vulns

11

Critical10
High0
Medium1
Low0
Affected Assets

11

11plugins
Avg CVSS

9.6

Average score of vulnerabilities

Researcher Submissions

11 records
2024-08-10 00:00CVE-2024-6924
10.0
Critical
Eddie Zhang (Project Black)Yes
2024-08-10 00:00CVE-2024-6928
10.0
Critical
Eddie Zhang (Project Black)Yes
2024-08-07 00:00CVE-2024-6926
10.0
Critical
Eddie Zhang (Project Black)No
2024-07-27 00:00CVE-2024-6459
9.8
Critical
Eddie Zhang (Project Black)Yes
2024-07-26 00:00CVE-2024-6460
9.8
Critical
Eddie Zhang (Project Black)Yes
2024-07-09 00:00CVE-2024-5765
10.0
Critical
Eddie Zhang (Project Black)No
2024-07-09 00:00CVE-2024-5975
10.0
Critical
Eddie Zhang (Project Black)No
2024-07-08 00:00CVE-2024-5882
6.1
Medium
Eddie Zhang (Project Black)Yes
2024-06-28 00:00CVE-2024-6205
10.0
Critical
Eddie Zhang (Project Black)Yes
2024-06-27 00:00CVE-2024-6164
9.8
Critical
Eddie Zhang (Project Black)Yes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C