Ivan Spiridonov (xbz0n)

Ivan Spiridonov (xbz0n) is a security researcher credited with 8 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #509 of 3,515 contributors. The disclosure was published in 2024.

Their research concentrates on SQL Injection, which accounts for 8 of their findings (100%). The average CVSS score across these disclosures is 8.9, peaking at 9.9. Severity breakdown: 6 critical and 2 high.

The most affected software includes AIKit - WordPress AI Automatic Writer (1), Burst Statistics (1), BWL Advanced FAQ Manager (1), across 8 distinct plugins, themes and core versions in total.

6 of the 8 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "AIKit <= 4.14.1 - Authenticated (Contributor+) SQL Injection", scores 9.9 out of 10.

2024
Critical
High
Medium
Low
Global Rank

#509

of 3,515 researchers

Vulns

8

Critical6
High2
Medium0
Low0
Affected Assets

8

8plugins
Avg CVSS

8.9

Average score of vulnerabilities

Researcher Submissions

8 records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C