Quốc Huy (jtwings)
Quốc Huy (jtwings) is a security researcher credited with 18 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #284 of 3,515 contributors. The disclosure was published in 2026.
Their research concentrates on Cross-Site Scripting, which accounts for 6 of their findings (33%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 5.9, peaking at 8.8. Severity breakdown: 0 critical and 3 high.
The most affected software includes Blocksy (2), Database for Contact Form 7 (1), Download Manager (1), across 17 distinct plugins, themes and core versions in total.
All 18 disclosed issues have since received a vendor fix. The most severe finding, "Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field", scores 8.8 out of 10.
#284
of 3,515 researchers
18
17
5.9
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C