Jerome Bruandet
Jerome Bruandet is a security researcher credited with 212 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #42 of 3,515 contributors. Their disclosures were published between 2016 and 2023. The most productive year was 2021, with 89 findings.
Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 73 of their findings (34%). Other recurring categories include Missing Authorization, Cross-Site Scripting. The average CVSS score across these disclosures is 6.5, peaking at 9.9. Severity breakdown: 32 critical and 55 high.
The most affected software includes Directory Listings WordPress plugin (9), Frontend File Manager Plugin (8), WP Quick FrontEnd Editor (4), across 164 distinct plugins, themes and core versions in total.
191 of the 212 disclosed issues have a vendor fix, while 21 remain unpatched. The most severe finding, "Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change", scores 9.9 out of 10.
#42
of 3,515 researchers
212
241
6.5
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C