Poli

Poli is a security researcher credited with 13 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #369 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 7 findings.

Their research concentrates on Missing Authorization, which accounts for 10 of their findings (77%). Other recurring categories include Exposure Of Sensitive Information Through Data Queries, Server-Side Request Forgery (SSRF). The average CVSS score across these disclosures is 5.3, peaking at 6.5.

The most affected software includes e-shot (2), MORKVA Vchasno Kasa Integration (2), Block Editor Gallery Slider… (1), across 11 distinct plugins, themes and core versions in total.

5 of the 13 disclosed issues have a vendor fix, while 8 remain unpatched.

20252026
Critical
High
Medium
Low
Global Rank

#369

of 3,515 researchers

Vulns

13

Critical0
High0
Medium13
Low0
Affected Assets

11

11plugins
Avg CVSS

5.3

Average score of vulnerabilities

Researcher Submissions

13 records
2026-04-14 19:45CVE-2026-3649
5.3
Medium
PoliNo
2026-04-14 19:45CVE-2026-3642
5.3
Medium
PoliNo
2026-04-07 15:25CVE-2026-3646
5.3
Medium
PoliYes
2026-03-20 15:09CVE-2026-3546
5.3
Medium
PoliNo
2026-03-20 15:09CVE-2026-3645
5.3
Medium
PoliNo
2026-03-20 15:09CVE-2026-3570
5.3
Medium
PoliNo
2026-03-19 19:51CVE-2026-3550
5.3
Medium
PoliYes
2025-07-28 20:26CVE-2025-6730
4.3
Medium
PoliNo
2025-07-18 17:11CVE-2025-6720
5.3
Medium
PoliYes
2025-07-18 00:00CVE-2025-6721
5.3
Medium
PoliYes
Showing 1–10 of 13 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C