Evan Ricafort
Evan Ricafort is a security researcher credited with 4 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #901 of 3,515 contributors. Their disclosures were published between 2019 and 2021. The most productive year was 2019, with 2 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 4 of their findings (100%). The average CVSS score across these disclosures is 6.3, peaking at 7.6. Severity breakdown: 0 critical and 1 high.
The most affected software includes WordPress 5.2 (2), WordPress 5.4 (1), WordPress WordPress (1), across 3 distinct plugins, themes and core versions in total.
All 4 disclosed issues have since received a vendor fix.
#901
of 3,515 researchers
4
2
6.3
Average score of vulnerabilities
Researcher Submissions
| 2021-09-09 00:00 | WordPress Core 5.8 beta - Stored Cross-Site Scripting in Custom HTML Block WordPress WordPress 5.8 beta 1 – 5.8 beta 2 | CVE-2021-39202 | 7.6 High | Evan Ricafort | Yes |
| 2020-04-29 00:00 | WordPress Core < 5.4.1 - Authenticated Cross-Site Scripting via Customizer WordPress 5.4 3.7 – 5.4 · 19 branches | CVE-2020-11025 | 5.8 Medium | Evan Ricafort | Yes |
| 2019-10-14 00:00 | WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting via Customizer WordPress 5.2 3.7 – 5.2.3 · 17 branches | CVE-2019-17674 | 5.5 Medium | Evan Ricafort | Yes |
| 2019-10-14 00:00 | WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting WordPress 5.2 3.7 – 5.2.3 · 18 branches | CVE-2019-17672 | 6.4 Medium | Evan Ricafort | Yes |
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C