Nguyen Ngoc Duc (duc193)

Nguyen Ngoc Duc (duc193) is a security researcher credited with 21 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #239 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Improper Authentication, which accounts for 4 of their findings (19%). Other recurring categories include SQL Injection, Unrestricted Upload Of File With Dangerous Type. The average CVSS score across these disclosures is 8.0, peaking at 9.8. Severity breakdown: 5 critical and 12 high.

The most affected software includes LoginPress Pro (3), Advanced Database Cleaner (1), Advanced Google reCAPTCHA (1), across 19 distinct plugins, themes and core versions in total.

20 of the 21 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#239

of 3,515 researchers

Vulns

21

Critical5
High12
Medium4
Low0
Affected Assets

19

19plugins
Avg CVSS

8.0

Average score of vulnerabilities

Researcher Submissions

21 records
2026-09-03 00:00CVE-2026-12483
7.5
High
Nguyen Ngoc Duc (duc193)Yes
2026-07-27 20:16CVE-2026-14516
7.5
High
Nguyen Ngoc Duc (duc193)Yes
2026-07-10 13:21CVE-2026-11426
6.5
Medium
Nguyen Ngoc Duc (duc193)Yes
2026-07-09 11:14CVE-2026-12597
8.1
High
Nguyen Ngoc Duc (duc193)Yes
2026-07-09 11:14CVE-2026-12595
8.1
High
Nguyen Ngoc Duc (duc193)Yes
2026-07-09 11:13CVE-2026-12598
8.1
High
Nguyen Ngoc Duc (duc193)Yes
2026-06-29 20:41CVE-2026-9711
9.8
Critical
Nguyen Ngoc Duc (duc193)No
2026-06-25 00:00CVE-2026-57700
9.8
Critical
Nguyen Ngoc Duc (duc193)Yes
2026-06-18 17:00CVE-2026-7515
9.8
Critical
Nguyen Ngoc Duc (duc193)Yes
2026-06-05 05:58CVE-2026-5415
8.8
High
Nguyen Ngoc Duc (duc193)Yes
Showing 1–10 of 21 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C