lucky_buddy

lucky_buddy is a security researcher credited with 29 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #190 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 25 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 18 of their findings (62%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Cross-Site Scripting. The average CVSS score across these disclosures is 6.2, peaking at 9.8. Severity breakdown: 2 critical and 9 high.

The most affected software includes Booster for WooCommerce (3), CITS Support svg (2), (Simply) Guest Author Name (1), across 26 distinct plugins, themes and core versions in total.

22 of the 29 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#190

of 3,515 researchers

Vulns

29

Critical2
High9
Medium18
Low0
Affected Assets

26

25plugins1theme
Avg CVSS

6.2

Average score of vulnerabilities

Researcher Submissions

29 records
2026-05-28 17:56CVE-2026-3655
9.8
Critical
lucky_buddyYes
2026-05-26 13:07CVE-2026-7493
5.3
Medium
lucky_buddyYes
2026-04-07 12:49CVE-2026-3499
8.8
High
lucky_buddyYes
2026-02-18 15:08CVE-2025-12821
8.8
High
lucky_buddyNo
2025-12-12 16:10CVE-2025-13077
7.5
High
lucky_buddyNo
2025-12-04 17:39CVE-2025-12374
9.8
Critical
lucky_buddyYes
2025-12-01 16:23CVE-2025-13606
6.5
Medium
lucky_buddyYes
2025-08-28 00:00CVE-2024-13342
8.1
High
lucky_buddyYes
2025-07-16 00:00CVE-2025-54022
4.3
Medium
lucky_buddyYes
2025-07-04 00:00CVE-2025-24764
6.4
Medium
lucky_buddyYes
Showing 1–10 of 29 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C