shaman0x01
shaman0x01 is a security researcher credited with 44 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #139 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 28 findings.
Their research concentrates on SQL Injection, which accounts for 14 of their findings (32%). Other recurring categories include Cross-Site Scripting, Missing Authorization. The average CVSS score across these disclosures is 7.0, peaking at 9.8. Severity breakdown: 7 critical and 11 high.
The most affected software includes Unlimited Elements For Elementor (5), KiviCare (3), LearnPress (3), across 33 distinct plugins, themes and core versions in total.
42 of the 44 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user", scores 9.8 out of 10.
#139
of 3,515 researchers
44
33
7.0
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C