Mike Montoya

Mike Montoya is a security researcher credited with 3 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #1,107 of 3,333 contributors. The disclosure was published in 2026.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 1 of their findings (33%). Other recurring categories include Cross-Site Scripting, Server-Side Request Forgery (SSRF). The average CVSS score across these disclosures is 5.7, peaking at 6.4.

The most affected software includes Easy Table of Contents (1), Embed PDF Viewer (1), HashThemes Demo Importer (1), across 3 distinct plugins, themes and core versions in total.

2 of the 3 disclosed issues have a vendor fix, while 1 remain unpatched.

2026
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C