Lucas Montes (NiRoX)
Lucas Montes (NiRoX) is a security researcher credited with 22 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #237 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 14 findings.
Their research concentrates on Missing Authorization, which accounts for 8 of their findings (36%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Server-Side Request Forgery (SSRF). The average CVSS score across these disclosures is 5.8, peaking at 9.8. Severity breakdown: 1 critical and 2 high.
The most affected software includes LearnPress (2), Ninja Forms (2), RSS Aggregator by Feedzy (2), across 19 distinct plugins, themes and core versions in total.
All 22 disclosed issues have since received a vendor fix. The most severe finding, "Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload", scores 9.8 out of 10.
#237
of 3,515 researchers
22
19
5.8
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C