luc

luc is a security researcher credited with 27 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #197 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2026, with 17 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 6 of their findings (22%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Incorrect Privilege Assignment. The average CVSS score across these disclosures is 7.4, peaking at 9.8. Severity breakdown: 7 critical and 9 high.

The most affected software includes ToneDen Shortcode (4), Boost (2), Simple Link Directory Pro - AI Powered (2), across 22 distinct plugins, themes and core versions in total.

17 of the 27 disclosed issues have a vendor fix, while 10 remain unpatched. The most severe finding, "LMS Elementor Pro <= 1.0.4 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#197

of 3,515 researchers

Vulns

27

Critical7
High9
Medium11
Low0
Affected Assets

22

18plugins4themes
Avg CVSS

7.4

Average score of vulnerabilities

Researcher Submissions

27 records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C