lhking

lhking is a security researcher credited with 8 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #492 of 3,333 contributors. The disclosure was published in 2026.

Their research concentrates on Cross-Site Scripting, which accounts for 3 of their findings (38%). Other recurring categories include Path Traversal, Improper Verification Of Cryptographic Signature. The average CVSS score across these disclosures is 7.8, peaking at 9.8. Severity breakdown: 1 critical and 6 high.

The most affected software includes Appointment Booking Plugin (1), GTM4WP (1), Page Builder by SiteOrigin (1), across 8 distinct plugins, themes and core versions in total.

All 8 disclosed issues have since received a vendor fix. The most severe finding, "SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#492

of 3,333 researchers

Vulns

8

Critical1
High6
Medium1
Low0
Affected Assets

8

8plugins
Avg CVSS

7.8

Average score of vulnerabilities

Researcher Submissions

8 records
2026-07-28 20:33CVE-2026-16597
7.2
High
lhkingYes
2026-07-24 17:42CVE-2026-10818
8.1
High
lhkingYes
2026-07-15 00:00CVE-2026-15013
9.8
Critical
lhkingYes
2026-07-02 05:38CVE-2026-7311
8.1
High
lhkingYes
2026-06-26 17:44CVE-2026-13295
6.4
Medium
lhkingYes
2026-05-29 20:38CVE-2026-7459
7.5
High
lhkingYes
2026-05-06 15:34CVE-2026-7252
8.1
High
lhkingYes
2026-05-05 18:41CVE-2026-7332
7.2
High
lhkingYes
Showing 1–8 of 8 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C