Ivan Kuzymchak

Ivan Kuzymchak is a security researcher credited with 23 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #231 of 3,515 contributors. Their disclosures were published between 2022 and 2026. The most productive year was 2023, with 12 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 15 of their findings (65%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 5.7, peaking at 9.8. Severity breakdown: 1 critical and 3 high.

The most affected software includes All in One SEO (3), Tag, Category, and Taxonomy Manager (3), WPvivid (3), across 15 distinct plugins, themes and core versions in total.

22 of the 23 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite", scores 9.8 out of 10.

20222023202420252026
Critical
High
Medium
Low
Global Rank

#231

of 3,515 researchers

Vulns

23

Critical1
High3
Medium18
Low1
Affected Assets

15

15plugins
Avg CVSS

5.7

Average score of vulnerabilities

Researcher Submissions

23 records
2026-06-29 16:51CVE-2026-12073
9.8
Critical
Ivan KuzymchakYes
2025-09-10 00:00CVE-2025-0763
4.3
Medium
Ivan KuzymchakNo
2025-05-18 16:21CVE-2025-2892
6.4
Medium
Ivan KuzymchakYes
2025-04-11 00:00CVE-2025-2269
6.1
Medium
Ivan KuzymchakYes
2025-03-21 00:00CVE-2025-0723
6.5
Medium
Ivan KuzymchakYes
2024-12-16 16:25CVE-2024-9624
7.6
High
Ivan KuzymchakYes
2024-10-25 00:00CVE-2024-9475
4.9
Medium
Ivan KuzymchakYes
2024-10-04 00:00CVE-2024-9528
4.9
Medium
Ivan KuzymchakYes
2024-09-23 00:00CVE-2023-5359
3.7
Low
Ivan KuzymchakYes
2024-05-21 00:00CVE-2024-2953
5.5
Medium
Ivan KuzymchakYes
Showing 1–10 of 23 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C