Jakub Herman
Jakub Herman is a security researcher credited with 106 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #70 of 3,515 contributors. The disclosure was published in 2026.
Their research concentrates on Missing Authorization, which accounts for 36 of their findings (34%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Code Injection. The average CVSS score across these disclosures is 6.1, peaking at 9.8. Severity breakdown: 7 critical and 31 high.
The most affected software includes Kirki (4), Events Manager (3), Forminator Forms (2), across 98 distinct plugins, themes and core versions in total.
99 of the 106 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "JetFormBuilder — Dynamic Blocks Form Builder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution", scores 9.8 out of 10.
#70
of 3,515 researchers
106
100
6.1
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C