Khang Duong

Khang Duong is a security researcher credited with 20 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #262 of 3,515 contributors. The disclosure was published in 2025.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 14 of their findings (70%). Other recurring categories include Cross-Site Scripting. The average CVSS score across these disclosures is 4.6, peaking at 6.4.

The most affected software includes Bubble Menu (1), Button Generator (1), Counter Box (1), across 20 distinct plugins, themes and core versions in total.

16 of the 20 disclosed issues have a vendor fix, while 4 remain unpatched.

2025
Critical
High
Medium
Low
Global Rank

#262

of 3,515 researchers

Vulns

20

Critical0
High0
Medium20
Low0
Affected Assets

20

20plugins
Avg CVSS

4.6

Average score of vulnerabilities

Researcher Submissions

20 records
2025-04-01 00:00CVE-2025-31778
6.4
Medium
Khang DuongYes
2025-04-01 00:00CVE-2025-31839
4.3
Medium
Khang DuongNo
2025-04-01 00:00CVE-2025-31840
4.3
Medium
Khang DuongNo
2025-03-27 00:00CVE-2025-30912
4.3
Medium
Khang DuongYes
2025-03-09 00:00CVE-2025-26910
6.1
Medium
Khang DuongYes
2025-03-05 21:11CVE-2025-1672
5.5
Medium
Khang DuongYes
2025-02-13 00:00CVE-2025-26561
5.5
Medium
Khang DuongNo
2025-02-03 00:00CVE-2025-22640
4.4
Medium
Khang DuongNo
2025-02-03 00:00CVE-2025-22637
4.3
Medium
Khang DuongYes
2025-02-03 00:00CVE-2025-25111
4.3
Medium
Khang DuongYes
Showing 1–10 of 20 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C