João Pedro Soares de Alcântara
João Pedro Soares de Alcântara is a security researcher credited with 1,009 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #1 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 511 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 653 of their findings (65%). Other recurring categories include PHP Remote File Inclusion, SQL Injection. The average CVSS score across these disclosures is 6.7, peaking at 9.9. Severity breakdown: 25 critical and 262 high.
The most affected software includes tagDiv Composer (5), TheGem Theme Elements (5), Travel Booking WordPress Theme (5), across 846 distinct plugins, themes and core versions in total.
480 of the 1,009 disclosed issues have a vendor fix, while 529 remain unpatched. The most severe finding, "Unite Gallery Lite <= 1.7.62 - Authenticated (Contributor+) SQL Injection", scores 9.9 out of 10.
#1
of 3,515 researchers
1,009
846
6.7
Average score of vulnerabilities
Researcher Submissions
Showing the 250 most recent of 1,009 records. Every record has its own page and is listed in the sitemap.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C