Ryan Kozak
Ryan Kozak is a security researcher credited with 29 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #188 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 26 findings.
Their research concentrates on Unrestricted Upload Of File With Dangerous Type, which accounts for 18 of their findings (62%). Other recurring categories include External Control Of File Name Or Path, Code Injection. The average CVSS score across these disclosures is 7.5, peaking at 10.0. Severity breakdown: 7 critical and 15 high.
The most affected software includes eMagicOne Store Manager for WooCommerce (4), g-FFL Cockpit (2), StoreEngine (2), across 23 distinct plugins, themes and core versions in total.
26 of the 29 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover", scores 10.0 out of 10.
#188
of 3,515 researchers
29
23
7.5
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C