Sarawut Poolkhet (MisterHelloz)

Sarawut Poolkhet (MisterHelloz) is a security researcher credited with 15 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #328 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 13 findings.

Their research concentrates on Missing Authorization, which accounts for 8 of their findings (53%). Other recurring categories include Path Traversal, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 6.8, peaking at 9.8. Severity breakdown: 1 critical and 6 high.

The most affected software includes Advanced Custom Fields (ACF®) (2), BuddyPress Xprofile Custom Field Types (1), Creator LMS (1), across 14 distinct plugins, themes and core versions in total.

14 of the 15 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#328

of 3,515 researchers

Vulns

15

Critical1
High6
Medium8
Low0
Affected Assets

14

14plugins
Avg CVSS

6.8

Average score of vulnerabilities

Researcher Submissions

15 records
2026-05-30 14:23CVE-2026-8382
5.3
Medium
Sarawut Poolkhet (MisterHelloz)Yes
2026-05-27 00:00N/A
5.3
Medium
Sarawut Poolkhet (MisterHelloz)Yes
2026-03-10 13:11CVE-2026-1781
6.5
Medium
Sarawut Poolkhet (MisterHelloz)Yes
2026-02-07 12:47CVE-2025-15100
8.8
High
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-30 00:00CVE-2025-14554
7.2
High
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-27 00:00CVE-2026-1056
9.8
Critical
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-23 23:36CVE-2025-13920
5.3
Medium
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-22 17:11CVE-2026-0927
5.3
Medium
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-22 00:00CVE-2025-14866
8.8
High
Sarawut Poolkhet (MisterHelloz)Yes
2026-01-20 01:48CVE-2025-15347
8.8
High
Sarawut Poolkhet (MisterHelloz)Yes
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C