Lenon Leite

Lenon Leite is a security researcher credited with 35 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #166 of 3,515 contributors. Their disclosures were published between 2016 and 2026. The most productive year was 2016, with 14 findings.

Their research concentrates on SQL Injection, which accounts for 29 of their findings (83%). Other recurring categories include External Control Of File Name Or Path, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 7.8, peaking at 9.8. Severity breakdown: 6 critical and 22 high.

The most affected software includes Hermit 音乐播放器 (2), Simple Personal Message (2), [GWA] AutoResponder (1), across 33 distinct plugins, themes and core versions in total.

14 of the 35 disclosed issues have a vendor fix, while 21 remain unpatched. The most severe finding, "Hermit 音乐播放器 <= 3.1.6 - Unauthenticated SQL Injection", scores 9.8 out of 10.

2017201820192020202120222023202420252026
Critical
High
Medium
Low
Global Rank

#166

of 3,515 researchers

Vulns

35

Critical6
High22
Medium7
Low0
Affected Assets

77

34plugins43themes
Avg CVSS

7.8

Average score of vulnerabilities

Researcher Submissions

35 records
2026-06-09 00:00CVE-2016-20063
6.5
Medium
Lenon LeiteNo
2022-07-19 00:00CVE-2022-30998
8.8
High
Lenon LeiteNo
2022-04-28 12:22CVE-2022-29411
9.8
Critical
Lenon LeiteNo
2022-04-28 12:01CVE-2022-29410
8.8
High
Lenon LeiteNo
2022-04-25 00:00CVE-2022-29419
8.8
High
Lenon LeiteNo
2022-01-27 00:00CVE-2021-44779
7.3
High
Lenon LeiteNo
2021-10-06 19:17CVE-2021-39317
8.8
High
Chloe ChamberlandNo
2020-12-04 00:00N/A
8.8
High
Lenon LeiteYes
2020-11-19 00:00N/A
4.3
Medium
Lenon LeiteYes
2020-10-22 00:00N/A
9.8
Critical
Lenon LeiteYes
Showing 1–10 of 35 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C