kr0d

kr0d is a security researcher credited with 117 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #64 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 104 findings.

Their research concentrates on Missing Authorization, which accounts for 46 of their findings (39%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Improper Authorization. The average CVSS score across these disclosures is 8.2, peaking at 10.0. Severity breakdown: 36 critical and 53 high.

The most affected software includes Flynax Bridge (4), IDonate (4), KiotViet Sync (4), across 96 distinct plugins, themes and core versions in total.

80 of the 117 disclosed issues have a vendor fix, while 37 remain unpatched. The most severe finding, "TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover", scores 10.0 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#64

of 3,515 researchers

Vulns

117

Critical36
High53
Medium27
Low1
Affected Assets

96

96plugins
Avg CVSS

8.2

Average score of vulnerabilities

Researcher Submissions

117 records
2026-07-28 19:51CVE-2025-10656
9.8
Critical
kr0dNo
2026-02-18 16:32CVE-2025-4521
8.8
High
kr0dYes
2026-02-18 00:00CVE-2025-12845
8.8
High
kr0dYes
2026-02-18 00:00CVE-2026-1219
5.3
Medium
kr0dYes
2026-02-17 16:14CVE-2026-1296
6.1
Medium
kr0dYes
2026-02-13 20:09CVE-2026-1249
5.0
Medium
kr0dYes
2026-01-27 21:31CVE-2025-14386
8.8
High
kr0dYes
2026-01-23 19:29CVE-2025-15516
4.3
Medium
kr0dYes
2026-01-15 00:30CVE-2025-13859
6.4
Medium
kr0dYes
2026-01-05 18:53CVE-2025-13812
4.3
Medium
kr0dYes
Showing 1–10 of 117 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C