kr0d
kr0d is a security researcher credited with 117 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #64 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 104 findings.
Their research concentrates on Missing Authorization, which accounts for 46 of their findings (39%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Improper Authorization. The average CVSS score across these disclosures is 8.2, peaking at 10.0. Severity breakdown: 36 critical and 53 high.
The most affected software includes Flynax Bridge (4), IDonate (4), KiotViet Sync (4), across 96 distinct plugins, themes and core versions in total.
80 of the 117 disclosed issues have a vendor fix, while 37 remain unpatched. The most severe finding, "TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover", scores 10.0 out of 10.
#64
of 3,515 researchers
117
96
8.2
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C