Powpy
Powpy is a security researcher credited with 36 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #164 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 25 findings.
Their research concentrates on Missing Authorization, which accounts for 10 of their findings (28%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 5.7, peaking at 9.8. Severity breakdown: 1 critical and 5 high.
The most affected software includes Flexible Refund for WooCommerce (2), Return Refund and Exchange… (2), Beaver Builder Page Builder (1), across 34 distinct plugins, themes and core versions in total.
30 of the 36 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action", scores 9.8 out of 10.
#164
of 3,515 researchers
36
34
5.7
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C