João G. Barbosa (4rCanJ0x!)

João G. Barbosa (4rCanJ0x!) is a security researcher credited with 42 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #149 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 41 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 38 of their findings (90%). Other recurring categories include PHP Remote File Inclusion. The average CVSS score across these disclosures is 6.5, peaking at 9.9. Severity breakdown: 1 critical and 3 high.

The most affected software includes Magical Addons For Elementor ( Theme… (2), Responsive Blocks (2), SKT Addons for Elementor (2), across 39 distinct plugins, themes and core versions in total.

36 of the 42 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion", scores 9.9 out of 10.

20242025
Critical
High
Medium
Low
Global Rank

#149

of 3,515 researchers

Vulns

42

Critical1
High3
Medium38
Low0
Affected Assets

39

39plugins
Avg CVSS

6.5

Average score of vulnerabilities

Researcher Submissions

42 records
2025-01-31 00:00CVE-2025-22697
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-12-02 00:00CVE-2024-54212
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-12-02 00:00CVE-2024-54211
5.5
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-12-02 00:00CVE-2024-54213
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-11-28 00:00CVE-2024-53786
6.4
Medium
João G. Barbosa (4rCanJ0x!)No
2024-11-01 00:00CVE-2024-51663
4.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-09-16 00:00CVE-2024-44049
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-08-29 00:00CVE-2024-44059
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-08-26 00:00CVE-2024-43946
6.4
Medium
João G. Barbosa (4rCanJ0x!)Yes
2024-08-26 00:00CVE-2024-43960
4.4
Medium
João G. Barbosa (4rCanJ0x!)No
Showing 1–10 of 42 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C