Jerome Bruandet

Jerome Bruandet is a security researcher credited with 212 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #42 of 3,515 contributors. Their disclosures were published between 2016 and 2023. The most productive year was 2021, with 89 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 73 of their findings (34%). Other recurring categories include Missing Authorization, Cross-Site Scripting. The average CVSS score across these disclosures is 6.5, peaking at 9.9. Severity breakdown: 32 critical and 55 high.

The most affected software includes Directory Listings WordPress plugin (9), Frontend File Manager Plugin (8), WP Quick FrontEnd Editor (4), across 164 distinct plugins, themes and core versions in total.

191 of the 212 disclosed issues have a vendor fix, while 21 remain unpatched. The most severe finding, "Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change", scores 9.9 out of 10.

20162017201820192020202120222023
Critical
High
Medium
Low
Global Rank

#42

of 3,515 researchers

Vulns

212

Critical32
High55
Medium125
Low0
Affected Assets

241

217plugins24themes
Avg CVSS

6.5

Average score of vulnerabilities

Researcher Submissions

212 records
2023-10-25 00:00N/A
8.8
High
Jerome BruandetNo
2023-06-03 00:00CVE-2023-3125
6.5
Medium
Jerome BruandetYes
2023-06-03 00:00CVE-2023-3126
4.3
Medium
Jerome BruandetYes
2023-03-28 00:00CVE-2023-3124
8.8
High
Jerome BruandetYes
2022-11-28 00:00CVE-2022-4948
4.3
Medium
Jerome BruandetYes
2022-04-04 00:00CVE-2022-4950
8.8
High
Jerome BruandetYes
2022-01-25 00:00CVE-2022-4949
8.8
High
Jerome BruandetYes
2021-11-12 00:00CVE-2021-42362
8.8
High
Jerome BruandetYes
2021-10-28 00:00CVE-2021-4340
9.8
Critical
Jerome BruandetYes
2021-10-05 00:00CVE-2021-4352
5.3
Medium
Jerome BruandetYes
Showing 1–10 of 212 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C