shaman0x01

shaman0x01 is a security researcher credited with 44 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #139 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 28 findings.

Their research concentrates on SQL Injection, which accounts for 14 of their findings (32%). Other recurring categories include Cross-Site Scripting, Missing Authorization. The average CVSS score across these disclosures is 7.0, peaking at 9.8. Severity breakdown: 7 critical and 11 high.

The most affected software includes Unlimited Elements For Elementor (5), KiviCare (3), LearnPress (3), across 33 distinct plugins, themes and core versions in total.

42 of the 44 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user", scores 9.8 out of 10.

20242025
Critical
High
Medium
Low
Global Rank

#139

of 3,515 researchers

Vulns

44

Critical7
High11
Medium26
Low0
Affected Assets

33

33plugins
Avg CVSS

7.0

Average score of vulnerabilities

Researcher Submissions

44 records
2025-07-01 14:49CVE-2026-15289
5.9
Medium
shaman0x01Yes
2025-04-24 09:45CVE-2025-1294
7.2
High
shaman0x01Yes
2025-03-25 22:25CVE-2024-13411
6.4
Medium
shaman0x01Yes
2025-03-21 19:39CVE-2024-13666
5.3
Medium
shaman0x01Yes
2025-03-06 00:00CVE-2024-12609
6.5
Medium
shaman0x01Yes
2025-03-06 00:00CVE-2024-12607
6.5
Medium
shaman0x01Yes
2025-03-03 19:48CVE-2025-0512
6.4
Medium
shaman0x01Yes
2025-02-18 19:35CVE-2024-13231
5.3
Medium
shaman0x01No
2025-02-17 00:00CVE-2025-0817
7.2
High
shaman0x01Yes
2025-02-11 21:55CVE-2025-0511
7.2
High
shaman0x01Yes
Showing 1–10 of 44 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C