Khaled Alenazi (Nxploited)

Khaled Alenazi (Nxploited) is a security researcher credited with 48 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #127 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 29 findings.

Their research concentrates on Missing Authorization, which accounts for 19 of their findings (40%). Other recurring categories include SQL Injection, Path Traversal. The average CVSS score across these disclosures is 7.7, peaking at 9.8. Severity breakdown: 15 critical and 18 high.

The most affected software includes Likes and Dislikes Plugin (2), AI Copilot (1), Ajax WooSearch (1), across 47 distinct plugins, themes and core versions in total.

22 of the 48 disclosed issues have a vendor fix, while 26 remain unpatched. The most severe finding, "Login Social <= 1.0.4 - Unauthenticated Privilege Escalation via Account Takeover", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#127

of 3,515 researchers

Vulns

48

Critical15
High18
Medium15
Low0
Affected Assets

48

46plugins2themes
Avg CVSS

7.7

Average score of vulnerabilities

Researcher Submissions

48 records
2026-08-06 00:00CVE-2026-16261
9.8
Critical
Khaled Alenazi (Nxploited)No
2026-08-06 00:00CVE-2026-12872
9.8
Critical
Khaled Alenazi (Nxploited)No
2026-08-06 00:00CVE-2026-16256
9.8
Critical
Khaled Alenazi (Nxploited)No
2026-08-06 00:00CVE-2025-15672
8.1
High
Khaled Alenazi (Nxploited)Yes
2026-07-30 16:55CVE-2026-14483
9.8
Critical
Khaled Alenazi (Nxploited)Yes
2026-07-08 19:20CVE-2026-14245
9.8
Critical
Khaled Alenazi (Nxploited)Yes
2026-06-26 00:00CVE-2026-11961
8.1
High
Khaled Alenazi (Nxploited)Yes
2026-06-26 00:00CVE-2026-9810
9.8
Critical
Khaled Alenazi (Nxploited)Yes
2026-06-24 00:00CVE-2026-12281
9.8
Critical
Khaled Alenazi (Nxploited)Yes
2026-04-02 00:00CVE-2025-15484
9.8
Critical
Khaled Alenazi (Nxploited)Yes
Showing 1–10 of 48 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C