h0xilo

h0xilo is a security researcher credited with 32 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #170 of 3,333 contributors. The disclosure was published in 2026.

Their research concentrates on SQL Injection, which accounts for 11 of their findings (34%). Other recurring categories include Improper Privilege Management, Cross-Site Scripting. The average CVSS score across these disclosures is 7.9, peaking at 9.8. Severity breakdown: 3 critical and 23 high.

The most affected software includes Wishlist Member (4), WP Review Slider Pro (4), ARMember Premium (3), across 21 distinct plugins, themes and core versions in total.

31 of the 32 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#170

of 3,333 researchers

Vulns

32

Critical3
High23
Medium6
Low0
Affected Assets

21

21plugins
Avg CVSS

7.9

Average score of vulnerabilities

Researcher Submissions

32 records
2026-07-27 23:51CVE-2026-15016
6.4
Medium
h0xiloYes
2026-07-27 16:37CVE-2026-6251
6.5
Medium
h0xiloYes
2026-07-15 20:26CVE-2026-13741
8.8
High
h0xiloYes
2026-07-15 19:04CVE-2026-7543
7.2
High
h0xiloYes
2026-07-10 12:58CVE-2026-13756
8.8
High
h0xiloYes
2026-07-01 21:02CVE-2026-8441
7.5
High
h0xiloYes
2026-06-30 17:17CVE-2026-11823
7.5
High
h0xiloYes
2026-06-23 13:57CVE-2026-3652
7.2
High
h0xiloNo
2026-06-15 20:44CVE-2026-8442
8.1
High
h0xiloYes
2026-06-15 18:29CVE-2026-8444
8.8
High
h0xiloYes
Showing 1–10 of 32 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C