Michelle Porter

Michelle Porter is a security researcher credited with 9 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #495 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2025, with 5 findings.

Their research concentrates on Missing Authorization, which accounts for 4 of their findings (44%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 5.4, peaking at 8.8. Severity breakdown: 0 critical and 2 high.

The most affected software includes ImagePress (2), Academy LMS (1), Academy LMS Pro (1), across 8 distinct plugins, themes and core versions in total.

8 of the 9 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover", scores 8.8 out of 10.

20242025
Critical
High
Medium
Low
Global Rank

#495

of 3,515 researchers

Vulns

9

Critical0
High2
Medium7
Low0
Affected Assets

9

9plugins
Avg CVSS

5.4

Average score of vulnerabilities

Researcher Submissions

9 records
2025-11-20 00:00CVE-2025-10054
4.3
Medium
Michelle PorterYes
2025-11-07 00:00CVE-2025-12099
7.2
High
Michelle PorterYes
2025-11-07 00:00CVE-2025-12098
5.3
Medium
Michelle PorterYes
2025-09-09 17:42CVE-2025-7049
8.8
High
Michelle PorterNo
2025-04-07 00:00CVE-2025-2876
5.3
Medium
Michelle PorterYes
2024-10-11 00:00CVE-2024-9778
4.3
Medium
Michelle PorterYes
2024-10-11 00:00CVE-2024-9824
4.3
Medium
Michelle PorterYes
2024-09-27 00:00CVE-2024-8189
4.4
Medium
Michelle PorterYes
2024-09-25 00:00CVE-2024-8771
4.3
Medium
Michelle PorterYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C