Sajjad Ahmad (jack_sparrow)

Sajjad Ahmad (jack_sparrow) is a security researcher credited with 4 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #979 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 3 findings.

Their research concentrates on Cross-Site Request Forgery (CSRF), which accounts for 1 of their findings (25%). Other recurring categories include Cross-Site Scripting, External Control Of File Name Or Path. The average CVSS score across these disclosures is 4.5, peaking at 4.9.

The most affected software includes Easy Digital Downloads (2), Reviews Feed (2), across 2 distinct plugins, themes and core versions in total.

All 4 disclosed issues have since received a vendor fix.

20242025
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C