Phat RiO
Phat RiO is a security researcher credited with 364 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #19 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 196 findings.
Their research concentrates on Missing Authorization, which accounts for 119 of their findings (33%). Other recurring categories include Deserialization Of Untrusted Data, PHP Remote File Inclusion. The average CVSS score across these disclosures is 6.8, peaking at 9.8. Severity breakdown: 41 critical and 147 high.
The most affected software includes Directory Listings WordPress plugin (7), The Grid (4), WeDesignTech Ultimate Booking Addon (4), across 300 distinct plugins, themes and core versions in total.
197 of the 364 disclosed issues have a vendor fix, while 167 remain unpatched. The most severe finding, "Support Board < 3.8.9 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.
#19
of 3,515 researchers
364
300
6.8
Average score of vulnerabilities
Researcher Submissions
Showing the 250 most recent of 364 records. Every record has its own page and is listed in the sitemap.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C