Leonid Semenenko (lsemenenko)

Leonid Semenenko (lsemenenko) is a security researcher credited with 13 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #352 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on SQL Injection, which accounts for 6 of their findings (46%). Other recurring categories include External Control Of File Name Or Path, Path Traversal. The average CVSS score across these disclosures is 7.6, peaking at 8.8. Severity breakdown: 0 critical and 11 high.

The most affected software includes wpForo Forum (3), Betheme (2), AMP for WP (1), across 10 distinct plugins, themes and core versions in total.

All 13 disclosed issues have since received a vendor fix. The most severe finding, "Betheme <= 28.4 - Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#352

of 3,515 researchers

Vulns

13

Critical0
High11
Medium2
Low0
Affected Assets

10

9plugins1theme
Avg CVSS

7.6

Average score of vulnerabilities

Researcher Submissions

13 records
2026-08-27 00:00CVE-2026-5097
7.5
High
Leonid Semenenko (lsemenenko)Yes
2026-07-07 23:19CVE-2026-6854
7.5
High
Leonid Semenenko (lsemenenko)Yes
2026-07-06 00:00CVE-2026-6101
7.5
High
Leonid Semenenko (lsemenenko)Yes
2026-05-18 00:00CVE-2026-8912
7.5
High
Leonid Semenenko (lsemenenko)Yes
2026-05-13 18:03CVE-2026-3892
8.1
High
Leonid Semenenko (lsemenenko)Yes
2026-05-04 22:35CVE-2026-6261
8.8
High
WebbernautYes
2026-05-04 21:38CVE-2026-6262
6.5
Medium
WebbernautYes
2026-05-01 19:15CVE-2026-6457
6.5
Medium
Leonid Semenenko (lsemenenko)Yes
2026-04-17 04:37CVE-2026-5718
8.1
High
Leonid Semenenko (lsemenenko)Yes
2026-04-15 21:35CVE-2026-3489
7.5
High
Leonid Semenenko (lsemenenko)Yes
Showing 1–10 of 13 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C