João G. Barbosa (4rCanJ0x!)
João G. Barbosa (4rCanJ0x!) is a security researcher credited with 42 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #149 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 41 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 38 of their findings (90%). Other recurring categories include PHP Remote File Inclusion. The average CVSS score across these disclosures is 6.5, peaking at 9.9. Severity breakdown: 1 critical and 3 high.
The most affected software includes Magical Addons For Elementor ( Theme… (2), Responsive Blocks (2), SKT Addons for Elementor (2), across 39 distinct plugins, themes and core versions in total.
36 of the 42 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion", scores 9.9 out of 10.
#149
of 3,515 researchers
42
39
6.5
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C