John Castro

John Castro is a security researcher credited with 14 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #343 of 3,515 contributors. Their disclosures were published between 2018 and 2024. The most productive year was 2024, with 4 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 7 of their findings (50%). Other recurring categories include SQL Injection, Improper Access Control. The average CVSS score across these disclosures is 6.8, peaking at 9.8. Severity breakdown: 2 critical and 3 high.

The most affected software includes User Profile Builder (2), 3CX Free Live Chat, Calls & Messaging (1), Advanced Contact form 7 DB (1), across 13 distinct plugins, themes and core versions in total.

12 of the 14 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass", scores 9.8 out of 10.

2018201920202021202220232024
Critical
High
Medium
Low
Global Rank

#343

of 3,515 researchers

Vulns

14

Critical2
High3
Medium9
Low0
Affected Assets

13

13plugins
Avg CVSS

6.8

Average score of vulnerabilities

Researcher Submissions

14 records
2024-09-19 00:00CVE-2024-9156
7.5
High
John CastroYes
2024-09-02 00:00CVE-2024-7846
6.4
Medium
John CastroYes
2024-08-13 00:00CVE-2024-6708
4.4
Medium
John CastroYes
2024-07-10 00:00CVE-2024-6695
9.8
Critical
John CastroYes
2022-05-04 10:07CVE-2021-36912
5.4
Medium
John CastroNo
2021-12-15 14:44CVE-2021-36888
9.8
Critical
John CastroYes
2021-10-07 10:22CVE-2021-36911
5.5
Medium
John CastroNo
2021-02-24 00:00N/A
8.8
High
John CastroYes
2020-09-05 00:00CVE-2020-36831
5.0
Medium
John CastroYes
2020-06-22 00:00N/A
6.1
Medium
John CastroYes
Showing 1–10 of 14 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C