h0xilo
h0xilo is a security researcher credited with 32 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #170 of 3,333 contributors. The disclosure was published in 2026.
Their research concentrates on SQL Injection, which accounts for 11 of their findings (34%). Other recurring categories include Improper Privilege Management, Cross-Site Scripting. The average CVSS score across these disclosures is 7.9, peaking at 9.8. Severity breakdown: 3 critical and 23 high.
The most affected software includes Wishlist Member (4), WP Review Slider Pro (4), ARMember Premium (3), across 21 distinct plugins, themes and core versions in total.
31 of the 32 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation", scores 9.8 out of 10.
#170
of 3,333 researchers
32
21
7.9
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C