Marcin Dudek (dudekmar)

Marcin Dudek (dudekmar) is a security researcher credited with 15 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #332 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 11 findings.

Their research concentrates on Missing Authorization, which accounts for 7 of their findings (47%). Other recurring categories include SQL Injection, Code Injection. The average CVSS score across these disclosures is 6.4, peaking at 9.8. Severity breakdown: 2 critical and 4 high.

The most affected software includes Advanced Custom Fields (1), Booking Calendar (1), Converter for Media (1), across 15 distinct plugins, themes and core versions in total.

All 15 disclosed issues have since received a vendor fix. The most severe finding, "Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#332

of 3,515 researchers

Vulns

15

Critical2
High4
Medium9
Low0
Affected Assets

15

15plugins
Avg CVSS

6.4

Average score of vulnerabilities

Researcher Submissions

15 records
2026-02-18 16:09CVE-2025-14342
4.3
Medium
Marcin Dudek (dudekmar)Yes
2026-02-18 00:00CVE-2025-14294
5.3
Medium
Marcin Dudek (dudekmar)Yes
2026-02-10 12:36CVE-2025-13431
6.5
Medium
Marcin Dudek (dudekmar)Yes
2026-01-06 20:40CVE-2025-13722
5.3
Medium
Marcin Dudek (dudekmar)Yes
2025-12-29 05:47CVE-2025-14280
5.3
Medium
Marcin Dudek (dudekmar)Yes
2025-12-23 16:17CVE-2025-13773
9.8
Critical
shark3yYes
2025-12-20 14:15CVE-2025-12980
7.5
High
Marcin Dudek (dudekmar)Yes
2025-12-18 18:13CVE-2025-13754
5.3
Medium
Marcin Dudek (dudekmar)Yes
2025-12-16 18:41CVE-2025-11924
7.5
High
Lucas Montes (NiRoX)Yes
2025-12-16 18:33CVE-2025-13750
4.3
Medium
Marcin Dudek (dudekmar)Yes
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C