Kévin Mosbahi (Mika)
Kévin Mosbahi (Mika) is a security researcher credited with 712 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #7 of 3,515 contributors. Their disclosures were published between 2017 and 2026. The most productive year was 2025, with 265 findings.
Their research concentrates on Missing Authorization, which accounts for 252 of their findings (35%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting. The average CVSS score across these disclosures is 5.6, peaking at 9.8. Severity breakdown: 26 critical and 75 high.
The most affected software includes Spam Protection (4), WP Mailster (4), Barcode Generator for WooCommerce (3), across 642 distinct plugins, themes and core versions in total.
366 of the 712 disclosed issues have a vendor fix, while 346 remain unpatched. The most severe finding, "Agency Toolkit <= 1.0.23 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.
#7
of 3,515 researchers
712
645
5.6
Average score of vulnerabilities
Researcher Submissions
Showing the 250 most recent of 712 records. Every record has its own page and is listed in the sitemap.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C