shark3y

shark3y is a security researcher credited with 43 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #145 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 23 findings.

Their research concentrates on Missing Authorization, which accounts for 16 of their findings (37%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 6.6, peaking at 9.8. Severity breakdown: 4 critical and 16 high.

The most affected software includes weMail (2), 10Web Booster (1), Ajax Load More (1), across 42 distinct plugins, themes and core versions in total.

41 of the 43 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#145

of 3,515 researchers

Vulns

43

Critical4
High16
Medium22
Low1
Affected Assets

42

42plugins
Avg CVSS

6.6

Average score of vulnerabilities

Researcher Submissions

43 records
2026-09-04 00:00CVE-2025-14945
5.4
Medium
shark3yYes
2026-05-04 13:32CVE-2026-1921
4.9
Medium
shark3yYes
2026-04-17 04:24CVE-2026-3464
8.8
High
shark3yYes
2026-03-25 17:26CVE-2026-1206
4.3
Medium
shark3yYes
2026-03-23 16:27CVE-2026-4283
9.1
Critical
shark3yYes
2026-03-04 00:00CVE-2026-1321
8.1
High
shark3yYes
2026-02-20 20:58CVE-2025-14339
6.5
Medium
shark3yYes
2026-02-18 16:16CVE-2025-14427
4.3
Medium
shark3yYes
2026-02-16 16:35CVE-2026-2592
7.7
High
shark3yYes
2026-02-13 19:48CVE-2026-1843
7.2
High
shark3yYes
Showing 1–10 of 43 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C