Ryan Kozak

Ryan Kozak is a security researcher credited with 29 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #188 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 26 findings.

Their research concentrates on Unrestricted Upload Of File With Dangerous Type, which accounts for 18 of their findings (62%). Other recurring categories include External Control Of File Name Or Path, Code Injection. The average CVSS score across these disclosures is 7.5, peaking at 10.0. Severity breakdown: 7 critical and 15 high.

The most affected software includes eMagicOne Store Manager for WooCommerce (4), g-FFL Cockpit (2), StoreEngine (2), across 23 distinct plugins, themes and core versions in total.

26 of the 29 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover", scores 10.0 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#188

of 3,515 researchers

Vulns

29

Critical7
High15
Medium7
Low0
Affected Assets

23

23plugins
Avg CVSS

7.5

Average score of vulnerabilities

Researcher Submissions

29 records
2026-06-05 14:20CVE-2026-7537
7.2
High
Ryan KozakYes
2026-01-23 19:03CVE-2025-13374
9.8
Critical
Ryan KozakNo
2025-12-05 17:38CVE-2025-12720
5.3
Medium
Ryan KozakYes
2025-12-05 17:38CVE-2025-12721
5.3
Medium
Ryan KozakYes
2025-12-05 16:45CVE-2025-12673
9.8
Critical
Ryan KozakYes
2025-12-04 16:31CVE-2025-12189
4.3
Medium
Ryan KozakYes
2025-12-03 00:39CVE-2025-13390
10.0
Critical
Ryan KozakYes
2025-12-02 14:25CVE-2025-12585
5.3
Medium
Ryan KozakYes
2025-11-25 09:45CVE-2025-13597
9.8
Critical
Ryan KozakYes
2025-11-25 09:39CVE-2025-13595
9.8
Critical
Ryan KozakYes
Showing 1–10 of 29 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C