Muhamad Hidayat
Muhamad Hidayat is a security researcher credited with 10 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #455 of 3,515 contributors. Their disclosures were published between 2022 and 2024. The most productive year was 2022, with 9 findings.
Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 4 of their findings (40%). Other recurring categories include Cross-Site Scripting, Missing Authorization. The average CVSS score across these disclosures is 6.0, peaking at 8.8. Severity breakdown: 0 critical and 2 high.
The most affected software includes AdRotate Banner Manager (2), Easy Digital Downloads (2), Booking for Appointments and Events… (1), across 8 distinct plugins, themes and core versions in total.
9 of the 10 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "JivoChat Live Chat – WP live chat plugin for WordPress <= 1.3.5.3 - Cross-Site Request Forgery to Cross-Site Scripting", scores 8.8 out of 10.
#455
of 3,515 researchers
10
8
6.0
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C