Gibran Abdillah

Gibran Abdillah is a security researcher credited with 10 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #431 of 3,515 contributors. Their disclosures were published between 2022 and 2026. The most productive year was 2026, with 3 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 3 of their findings (30%). Other recurring categories include Missing Authorization, Authentication Bypass Using An Alternate Path Or Channel. The average CVSS score across these disclosures is 8.0, peaking at 9.8. Severity breakdown: 2 critical and 5 high.

The most affected software includes App Builder (1), Appointment Booking Calendar Plugin… (1), Jquery Validation For Contact Form 7 (1), across 10 distinct plugins, themes and core versions in total.

9 of the 10 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover", scores 9.8 out of 10.

20222023202420252026
Critical
High
Medium
Low
Global Rank

#431

of 3,515 researchers

Vulns

10

Critical2
High5
Medium3
Low0
Affected Assets

10

7plugins3themes
Avg CVSS

8.0

Average score of vulnerabilities

Researcher Submissions

10 records
2026-03-20 15:06CVE-2026-2375
6.5
Medium
Gibran AbdillahNo
2026-03-17 00:00CVE-2026-2991
7.3
High
Gibran AbdillahYes
2026-02-09 18:54CVE-2026-1722
5.3
Medium
Gibran AbdillahYes
2025-04-30 00:00CVE-2025-1305
8.8
High
Gibran AbdillahYes
2025-03-03 15:46CVE-2025-1306
8.8
High
Gibran AbdillahYes
2024-08-07 00:00CVE-2024-7350
9.8
Critical
Gibran AbdillahYes
2024-06-19 00:00CVE-2023-3204
6.5
Medium
Gibran AbdillahYes
2024-06-18 00:00CVE-2024-3229
9.8
Critical
Gibran AbdillahYes
2023-11-07 00:00CVE-2023-5235
8.8
High
Gibran AbdillahYes
2022-06-27 00:00CVE-2022-2144
8.8
High
Gibran AbdillahYes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C