Marc-Alexandre Montpas

Marc-Alexandre Montpas is a security researcher credited with 54 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #111 of 3,515 contributors. Their disclosures were published between 2014 and 2025. The most productive year was 2023, with 13 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 21 of their findings (39%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 7.8, peaking at 9.9. Severity breakdown: 15 critical and 20 high.

The most affected software includes All in One SEO (5), Patreon WordPress (5), Jetpack (3), across 37 distinct plugins, themes and core versions in total.

All 54 disclosed issues have since received a vendor fix. The most severe finding, "UpdraftPlus WordPress Backup Plugin <= 1.9.50 - Nonce Leak to Authorization Bypass", scores 9.9 out of 10.

2016201720182019202020212022202320242025
Critical
High
Medium
Low
Global Rank

#111

of 3,515 researchers

Vulns

54

Critical15
High20
Medium19
Low0
Affected Assets

39

34plugins1theme4core versions
Avg CVSS

7.8

Average score of vulnerabilities

Researcher Submissions

54 records
2025-10-15 00:00CVE-2025-10567
6.1
Medium
Marc-Alexandre MontpasYes
2025-05-13 00:00CVE-2025-3662
7.2
High
Marc-Alexandre MontpasYes
2024-10-17 00:00CVE-2024-10075
6.5
Medium
Marc-Alexandre MontpasYes
2024-10-17 00:00CVE-2024-10076
6.4
Medium
Marc-Alexandre MontpasYes
2024-05-14 00:00CVE-2024-4180
6.1
Medium
Marc-Alexandre MontpasYes
2024-01-31 00:00CVE-2023-5124
4.4
Medium
Marc-Alexandre MontpasYes
2023-12-21 00:00CVE-2023-6623
9.8
Critical
Marc-Alexandre MontpasYes
2023-12-18 00:00CVE-2023-6627
6.1
Medium
Marc-Alexandre MontpasYes
2023-12-11 00:00CVE-2023-6000
6.1
Medium
Marc-Alexandre MontpasYes
2023-11-24 00:00CVE-2023-6584
9.8
Critical
Marc-Alexandre MontpasYes
Showing 1–10 of 54 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C