James Golovich

James Golovich is a security researcher credited with 50 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #119 of 3,515 contributors. Their disclosures were published between 2014 and 2023. The most productive year was 2016, with 31 findings.

Their research concentrates on Missing Authorization, which accounts for 22 of their findings (44%). Other recurring categories include Improper Privilege Management, Unrestricted Upload Of File With Dangerous Type. The average CVSS score across these disclosures is 7.7, peaking at 9.9. Severity breakdown: 14 critical and 18 high.

The most affected software includes WP-Invoice (6), Download Manager (3), Ultimate Member (3), across 37 distinct plugins, themes and core versions in total.

All 50 disclosed issues have since received a vendor fix. The most severe finding, "Simple Download Monitor <= 3.2.8 - Missing Authorization", scores 9.9 out of 10.

2014201520162017201820192020202120222023
Critical
High
Medium
Low
Global Rank

#119

of 3,515 researchers

Vulns

50

Critical14
High18
Medium18
Low0
Affected Assets

50

41plugins8themes1core version
Avg CVSS

7.7

Average score of vulnerabilities

Researcher Submissions

50 records
2023-10-12 00:00N/A
5.4
Medium
James GolovichYes
2022-10-03 00:00CVE-2022-2594
4.3
Medium
James GolovichYes
2022-07-14 00:00CVE-2022-2594
4.3
Medium
James GolovichYes
2020-02-19 00:00N/A
6.1
Medium
James GolovichYes
2019-08-20 00:00CVE-2015-9331
7.5
High
James GolovichYes
2018-11-12 00:00N/A
7.3
High
James GolovichYes
2017-11-27 00:00CVE-2017-18596
8.8
High
James GolovichYes
2017-05-05 00:00N/A
6.5
Medium
James GolovichYes
2017-04-17 00:00N/A
5.3
Medium
James GolovichYes
2017-04-17 00:00N/A
9.8
Critical
James GolovichYes
Showing 1–10 of 50 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C