Kévin Mosbahi (Mika)

Kévin Mosbahi (Mika) is a security researcher credited with 712 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #7 of 3,515 contributors. Their disclosures were published between 2017 and 2026. The most productive year was 2025, with 265 findings.

Their research concentrates on Missing Authorization, which accounts for 252 of their findings (35%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting. The average CVSS score across these disclosures is 5.6, peaking at 9.8. Severity breakdown: 26 critical and 75 high.

The most affected software includes Spam Protection (4), WP Mailster (4), Barcode Generator for WooCommerce (3), across 642 distinct plugins, themes and core versions in total.

366 of the 712 disclosed issues have a vendor fix, while 346 remain unpatched. The most severe finding, "Agency Toolkit <= 1.0.23 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.

2017201820192020202120222023202420252026
Critical
High
Medium
Low
Global Rank

#7

of 3,515 researchers

Vulns

712

Critical26
High75
Medium610
Low1
Affected Assets

645

633plugins12themes
Avg CVSS

5.6

Average score of vulnerabilities

Researcher Submissions

712 records
2026-04-15 00:00CVE-2025-15635
4.3
Medium
Kévin Mosbahi (Mika)Yes
2026-02-03 00:00CVE-2025-22657
5.3
Medium
Kévin Mosbahi (Mika)Yes
2026-01-06 00:00CVE-2024-49249
8.1
High
Kévin Mosbahi (Mika)Yes
2025-12-18 00:00CVE-2024-56066
9.8
Critical
Kévin Mosbahi (Mika)Yes
2025-12-05 00:00CVE-2024-54229
9.8
Critical
Kévin Mosbahi (Mika)No
2025-11-13 00:00CVE-2024-52416
9.8
Critical
Kévin Mosbahi (Mika)No
2025-11-13 00:00CVE-2025-64271
4.3
Medium
Kévin Mosbahi (Mika)Yes
2025-11-12 00:00CVE-2025-67472
4.3
Medium
Kévin Mosbahi (Mika)Yes
2025-11-12 00:00CVE-2025-67559
4.3
Medium
Kévin Mosbahi (Mika)Yes
2025-09-27 00:00CVE-2025-62901
6.4
Medium
Kévin Mosbahi (Mika)No
Showing 1–10 of 250 reports

Showing the 250 most recent of 712 records. Every record has its own page and is listed in the sitemap.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C