Ivan Kuzymchak
Ivan Kuzymchak is a security researcher credited with 23 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #231 of 3,515 contributors. Their disclosures were published between 2022 and 2026. The most productive year was 2023, with 12 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 15 of their findings (65%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 5.7, peaking at 9.8. Severity breakdown: 1 critical and 3 high.
The most affected software includes All in One SEO (3), Tag, Category, and Taxonomy Manager (3), WPvivid (3), across 15 distinct plugins, themes and core versions in total.
22 of the 23 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite", scores 9.8 out of 10.
#231
of 3,515 researchers
23
15
5.7
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C