Powpy

Powpy is a security researcher credited with 36 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #164 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 25 findings.

Their research concentrates on Missing Authorization, which accounts for 10 of their findings (28%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 5.7, peaking at 9.8. Severity breakdown: 1 critical and 5 high.

The most affected software includes Flexible Refund for WooCommerce (2), Return Refund and Exchange… (2), Beaver Builder Page Builder (1), across 34 distinct plugins, themes and core versions in total.

30 of the 36 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#164

of 3,515 researchers

Vulns

36

Critical1
High5
Medium30
Low0
Affected Assets

34

34plugins
Avg CVSS

5.7

Average score of vulnerabilities

Researcher Submissions

36 records
2026-06-18 16:09CVE-2026-1856
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-02-18 16:21CVE-2025-14452
7.2
High
Athiwat Tiprasaharn (Jitlada)Yes
2026-02-18 00:00CVE-2025-12707
7.5
High
Athiwat Tiprasaharn (Jitlada)Yes
2026-02-13 18:33CVE-2026-1306
9.8
Critical
Athiwat Tiprasaharn (Jitlada)Yes
2026-01-27 17:21CVE-2025-14610
7.2
High
Athiwat Tiprasaharn (Jitlada)Yes
2026-01-13 16:43CVE-2026-0694
6.4
Medium
Athiwat Tiprasaharn (Jitlada)No
2026-01-09 00:00CVE-2025-14506
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-01-08 21:20CVE-2025-11453
6.4
Medium
PowpyYes
2026-01-06 20:39CVE-2025-14453
6.4
Medium
Athiwat Tiprasaharn (Jitlada)No
2026-01-06 20:35CVE-2025-14626
6.4
Medium
Athiwat Tiprasaharn (Jitlada)No
Showing 1–10 of 36 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C