Jonah Burgess (CryptoCat)

Jonah Burgess (CryptoCat) is a security researcher credited with 9 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #454 of 3,333 contributors. The disclosure was published in 2026.

Their research concentrates on Cross-Site Scripting, which accounts for 4 of their findings (44%). Other recurring categories include SQL Injection, Missing Authorization. The average CVSS score across these disclosures is 6.8, peaking at 8.8. Severity breakdown: 0 critical and 2 high.

The most affected software includes ProfileGrid (3), Essential Addons for Elementor (2), Database for Contact Form 7 (1), across 6 distinct plugins, themes and core versions in total.

All 9 disclosed issues have since received a vendor fix. The most severe finding, "Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#454

of 3,333 researchers

Vulns

9

Critical0
High2
Medium7
Low0
Affected Assets

6

6plugins
Avg CVSS

6.8

Average score of vulnerabilities

Researcher Submissions

9 records
2026-08-06 00:53CVE-2026-18501
6.4
Medium
Jonah Burgess (CryptoCat)Yes
2026-07-20 16:10CVE-2026-15156
6.4
Medium
Jonah Burgess (CryptoCat)Yes
2026-07-10 16:46CVE-2026-15155
8.8
High
Jonah Burgess (CryptoCat)Yes
2026-07-01 21:05CVE-2026-9145
6.5
Medium
Jonah Burgess (CryptoCat)Yes
2026-06-22 00:00CVE-2026-4610
6.4
Medium
Jonah Burgess (CryptoCat)Yes
2026-06-05 15:34CVE-2026-9829
6.5
Medium
Jonah Burgess (CryptoCat)Yes
2026-05-12 00:00CVE-2026-4608
6.5
Medium
Jonah Burgess (CryptoCat)Yes
2026-05-12 00:00CVE-2026-4609
7.1
High
Jonah Burgess (CryptoCat)Yes
2026-04-30 00:00CVE-2026-6127
6.4
Medium
Jonah Burgess (CryptoCat)Yes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C