lucky_buddy
lucky_buddy is a security researcher credited with 29 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #190 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 25 findings.
Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 18 of their findings (62%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Cross-Site Scripting. The average CVSS score across these disclosures is 6.2, peaking at 9.8. Severity breakdown: 2 critical and 9 high.
The most affected software includes Booster for WooCommerce (3), CITS Support svg (2), (Simply) Guest Author Name (1), across 26 distinct plugins, themes and core versions in total.
22 of the 29 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification", scores 9.8 out of 10.
#190
of 3,515 researchers
29
26
6.2
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C