Ivan Cese

Ivan Cese is a security researcher credited with 31 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #183 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 24 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 11 of their findings (35%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization. The average CVSS score across these disclosures is 5.6, peaking at 8.8. Severity breakdown: 0 critical and 6 high.

The most affected software includes CSV to SortTable (2), ProjectList (2), The Bucketlister (2), across 28 distinct plugins, themes and core versions in total.

6 of the 31 disclosed issues have a vendor fix, while 25 remain unpatched. The most severe finding, "Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion", scores 8.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#183

of 3,515 researchers

Vulns

31

Critical0
High6
Medium25
Low0
Affected Assets

28

28plugins
Avg CVSS

5.6

Average score of vulnerabilities

Researcher Submissions

31 records
2026-04-15 18:53CVE-2025-14868
8.8
High
Ivan CeseYes
2026-02-06 20:26CVE-2025-15476
4.3
Medium
Ivan CeseNo
2026-02-06 20:26CVE-2025-15477
6.5
Medium
Ivan CeseNo
2026-02-05 18:34CVE-2026-1909
6.4
Medium
Ivan CeseYes
2026-01-13 17:19CVE-2025-14613
7.2
High
Ivan CeseNo
2026-01-13 16:44CVE-2025-14464
5.3
Medium
Ivan CeseNo
2026-01-06 20:30CVE-2025-13694
5.3
Medium
Ivan CeseNo
2025-12-12 16:11CVE-2025-14539
5.4
Medium
Ivan CeseNo
2025-12-12 16:09CVE-2025-14451
4.7
Medium
Ivan CeseNo
2025-12-11 19:26CVE-2025-12960
6.5
Medium
Ivan CeseYes
Showing 1–10 of 31 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C