Ren Voza

Ren Voza is a security researcher credited with 11 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #394 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 10 findings.

Their research concentrates on Missing Authorization, which accounts for 3 of their findings (27%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Code Injection. The average CVSS score across these disclosures is 7.9, peaking at 9.8. Severity breakdown: 3 critical and 5 high.

The most affected software includes Account Switcher (1), AcyMailing (1), App Builder (1), across 11 distinct plugins, themes and core versions in total.

8 of the 11 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "Woocommerce Custom Product Addons Pro <= 5.4.1 - Unauthenticated Remote Code Execution via Custom Pricing Formula", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#394

of 3,515 researchers

Vulns

11

Critical3
High5
Medium3
Low0
Affected Assets

11

11plugins
Avg CVSS

7.9

Average score of vulnerabilities

Researcher Submissions

11 records
2026-08-27 00:00CVE-2026-4246
6.1
Medium
Ren VozaYes
2026-07-10 14:18CVE-2026-7544
4.3
Medium
Ren VozaYes
2026-05-28 14:22CVE-2026-4290
9.1
Critical
Ren VozaNo
2026-05-19 12:05CVE-2026-6456
8.8
High
Ren VozaNo
2026-05-14 00:00CVE-2026-4094
8.1
High
Ren VozaYes
2026-05-04 17:38CVE-2026-4304
7.5
High
Ren VozaYes
2026-05-01 15:33CVE-2026-7638
5.3
Medium
Ren VozaNo
2026-04-15 16:43CVE-2026-3614
8.8
High
Ren VozaYes
2026-03-23 10:53CVE-2026-4001
9.8
Critical
Ren VozaYes
2026-03-02 04:48CVE-2026-3132
8.8
High
Ren VozaYes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C