GiongfNef

GiongfNef is a security researcher credited with 10 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #465 of 3,515 contributors. Their disclosures were published between 2023 and 2024. The most productive year was 2024, with 9 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 5 of their findings (50%). Other recurring categories include Missing Authorization. The average CVSS score across these disclosures is 5.0, peaking at 8.8. Severity breakdown: 0 critical and 1 high.

The most affected software includes LadiApp (8), Microsoft Clarity (1), WP EXtra (1), across 3 distinct plugins, themes and core versions in total.

2 of the 10 disclosed issues have a vendor fix, while 8 remain unpatched. The most severe finding, "WP EXtra <= 6.2 - Missing Authorization to .htaccess File Modification", scores 8.8 out of 10.

20232024
Critical
High
Medium
Low
Global Rank

#465

of 3,515 researchers

Vulns

10

Critical0
High1
Medium9
Low0
Affected Assets

3

3plugins
Avg CVSS

5.0

Average score of vulnerabilities

Researcher Submissions

10 records
2024-08-16 00:00CVE-2023-4730
5.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4628
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4731
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4626
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4728
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4627
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4729
4.3
Medium
GiongfNefNo
2024-03-11 00:00CVE-2023-4629
4.3
Medium
GiongfNefNo
2024-02-16 00:00CVE-2024-0590
6.1
Medium
GiongfNefYes
2023-10-24 00:00CVE-2023-5311
8.8
High
GiongfNefYes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C