Khaled Alenazi (Nxploited)
Khaled Alenazi (Nxploited) is a security researcher credited with 48 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #127 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 29 findings.
Their research concentrates on Missing Authorization, which accounts for 19 of their findings (40%). Other recurring categories include SQL Injection, Path Traversal. The average CVSS score across these disclosures is 7.7, peaking at 9.8. Severity breakdown: 15 critical and 18 high.
The most affected software includes Likes and Dislikes Plugin (2), AI Copilot (1), Ajax WooSearch (1), across 47 distinct plugins, themes and core versions in total.
22 of the 48 disclosed issues have a vendor fix, while 26 remain unpatched. The most severe finding, "Login Social <= 1.0.4 - Unauthenticated Privilege Escalation via Account Takeover", scores 9.8 out of 10.
#127
of 3,515 researchers
48
48
7.7
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C