Hunter Jensen (skid)

Hunter Jensen (skid) is a security researcher credited with 10 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #446 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Missing Authorization, which accounts for 4 of their findings (40%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Scripting. The average CVSS score across these disclosures is 6.5, peaking at 8.8. Severity breakdown: 0 critical and 4 high.

The most affected software includes AWP Classifieds (1), Booking for Appointments and Events… (1), Calculated Fields Form (1), across 10 distinct plugins, themes and core versions in total.

9 of the 10 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "Amelia Booking 8.3 - 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#446

of 3,515 researchers

Vulns

10

Critical0
High4
Medium6
Low0
Affected Assets

10

10plugins
Avg CVSS

6.5

Average score of vulnerabilities

Researcher Submissions

10 records
2026-06-10 13:18CVE-2026-2827
4.7
Medium
Hunter Jensen (skid)Yes
2026-05-19 12:03CVE-2026-6072
6.5
Medium
Hunter Jensen (skid)Yes
2026-05-04 19:57CVE-2026-3601
4.3
Medium
Hunter Jensen (skid)Yes
2026-05-04 14:11CVE-2026-5100
7.5
High
Hunter Jensen (skid)Yes
2026-04-10 12:00CVE-2026-3371
4.3
Medium
Hunter Jensen (skid)Yes
2026-04-07 15:21CVE-2026-4299
5.3
Medium
Hunter Jensen (skid)Yes
2026-03-25 15:31CVE-2026-2931
8.8
High
Hunter Jensen (skid)Yes
2026-03-25 12:44CVE-2026-4484
8.8
High
Hunter Jensen (skid)Yes
2026-03-20 14:37CVE-2026-4261
8.8
High
Hunter Jensen (skid)No
2026-03-12 19:59CVE-2026-3986
6.4
Medium
Hunter Jensen (skid)Yes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C