Quốc Huy (jtwings)

Quốc Huy (jtwings) is a security researcher credited with 18 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #284 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Cross-Site Scripting, which accounts for 6 of their findings (33%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 5.9, peaking at 8.8. Severity breakdown: 0 critical and 3 high.

The most affected software includes Blocksy (2), Database for Contact Form 7 (1), Download Manager (1), across 17 distinct plugins, themes and core versions in total.

All 18 disclosed issues have since received a vendor fix. The most severe finding, "Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#284

of 3,515 researchers

Vulns

18

Critical0
High3
Medium15
Low0
Affected Assets

17

16plugins1theme
Avg CVSS

5.9

Average score of vulnerabilities

Researcher Submissions

18 records
2026-08-21 00:00CVE-2026-4245
4.3
Medium
Quốc Huy (jtwings)Yes
2026-07-23 18:30CVE-2026-15755
6.4
Medium
Quốc Huy (jtwings)Yes
2026-07-23 14:27CVE-2026-6454
6.4
Medium
Quốc Huy (jtwings)Yes
2026-06-08 20:11CVE-2026-8365
8.8
High
Quốc Huy (jtwings)Yes
2026-05-27 10:58CVE-2026-4888
4.3
Medium
Quốc Huy (jtwings)Yes
2026-04-10 11:56CVE-2026-5217
7.2
High
Quốc Huy (jtwings)Yes
2026-03-31 12:23CVE-2026-3831
4.3
Medium
Quốc Huy (jtwings)Yes
2026-03-18 00:00CVE-2026-2571
4.3
Medium
Quốc Huy (jtwings)Yes
2026-03-16 15:17CVE-2026-2373
5.3
Medium
Quốc Huy (jtwings)Yes
2026-03-12 19:30CVE-2026-2257
6.4
Medium
Quốc Huy (jtwings)Yes
Showing 1–10 of 18 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C