Kazuma Matsumoto

Kazuma Matsumoto is a security researcher credited with 25 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #219 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Missing Authorization, which accounts for 9 of their findings (36%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 5.5, peaking at 8.8. Severity breakdown: 0 critical and 4 high.

The most affected software includes AI Copilot (5), Booktics (2), Meta-box GalleryMeta (2), across 18 distinct plugins, themes and core versions in total.

22 of the 25 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#219

of 3,515 researchers

Vulns

25

Critical0
High4
Medium21
Low0
Affected Assets

18

18plugins
Avg CVSS

5.5

Average score of vulnerabilities

Researcher Submissions

25 records
2026-08-04 17:34CVE-2026-6639
7.5
High
Kazuma MatsumotoYes
2026-07-10 18:57CVE-2026-1359
8.8
High
Kazuma MatsumotoYes
2026-07-10 15:30CVE-2026-3552
4.3
Medium
Kazuma MatsumotoYes
2026-07-10 15:18CVE-2026-6804
5.3
Medium
Kazuma MatsumotoYes
2026-07-10 15:17CVE-2026-6803
5.3
Medium
Kazuma MatsumotoYes
2026-05-19 17:23CVE-2026-2955
6.4
Medium
Kazuma MatsumotoYes
2026-05-11 20:38CVE-2026-6813
4.4
Medium
Kazuma MatsumotoNo
2026-05-11 20:37CVE-2026-6800
4.4
Medium
Kazuma MatsumotoYes
2026-05-11 19:07CVE-2026-2993
7.5
High
Kazuma MatsumotoYes
2026-04-20 18:26CVE-2026-6712
4.4
Medium
Kazuma MatsumotoYes
Showing 1–10 of 25 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C