Marc-Alexandre Montpas
Marc-Alexandre Montpas is a security researcher credited with 54 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #111 of 3,515 contributors. Their disclosures were published between 2014 and 2025. The most productive year was 2023, with 13 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 21 of their findings (39%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 7.8, peaking at 9.9. Severity breakdown: 15 critical and 20 high.
The most affected software includes All in One SEO (5), Patreon WordPress (5), Jetpack (3), across 37 distinct plugins, themes and core versions in total.
All 54 disclosed issues have since received a vendor fix. The most severe finding, "UpdraftPlus WordPress Backup Plugin <= 1.9.50 - Nonce Leak to Authorization Bypass", scores 9.9 out of 10.
#111
of 3,515 researchers
54
39
7.8
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C