sergioframi

sergioframi is a security researcher credited with 3 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #1,140 of 3,515 contributors. The disclosure was published in 2025.

Their research concentrates on Improper Access Control, which accounts for 1 of their findings (33%). Other recurring categories include Improper Authorization, SQL Injection. The average CVSS score across these disclosures is 6.2, peaking at 8.8. Severity breakdown: 0 critical and 1 high.

The most affected software includes Tutor LMS Pro (2), Tutor LMS (1), across 2 distinct plugins, themes and core versions in total.

All 3 disclosed issues have since received a vendor fix. The most severe finding, "Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection", scores 8.8 out of 10.

2025
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C