shark3y
shark3y is a security researcher credited with 43 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #145 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 23 findings.
Their research concentrates on Missing Authorization, which accounts for 16 of their findings (37%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key. The average CVSS score across these disclosures is 6.6, peaking at 9.8. Severity breakdown: 4 critical and 16 high.
The most affected software includes weMail (2), 10Web Booster (1), Ajax Load More (1), across 42 distinct plugins, themes and core versions in total.
41 of the 43 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution", scores 9.8 out of 10.
#145
of 3,515 researchers
43
42
6.6
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C