Shivamani Vastrala

Shivamani Vastrala is a security researcher credited with 30 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #174 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Missing Authorization, which accounts for 11 of their findings (37%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Scripting. The average CVSS score across these disclosures is 5.5, peaking at 9.8. Severity breakdown: 1 critical and 2 high.

The most affected software includes Abandoned Cart Lite for WooCommerce (1), Admin Columns for ACF Fields (1), AI Engine (1), across 30 distinct plugins, themes and core versions in total.

27 of the 30 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "Abandoned Cart Lite for WooCommerce <= 6.8.1 - Unauthenticated Privilege Escalation via Weak Recovery Link", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#174

of 3,515 researchers

Vulns

33

Critical1
High2
Medium30
Low0
Affected Assets

33

33plugins
Avg CVSS

5.5

Average score of vulnerabilities

Researcher Submissions

30 records
2026-08-26 00:00CVE-2026-78146
5.3
Medium
Shivamani VastralaYes
2026-08-24 00:00CVE-2026-13404
5.3
Medium
Shivamani VastralaYes
2026-08-21 00:00CVE-2026-16058
5.3
Medium
Shivamani VastralaYes
2026-08-20 00:00CVE-2026-15384
4.3
Medium
Shivamani VastralaYes
2026-08-14 00:00CVE-2026-15388
4.3
Medium
Shivamani VastralaYes
2026-08-13 00:00CVE-2026-16611
5.3
Medium
Shivamani VastralaYes
2026-08-13 00:00CVE-2026-14230
6.4
Medium
Shivamani VastralaYes
2026-08-03 00:00CVE-2026-16957
4.3
Medium
Shivamani VastralaYes
2026-08-03 00:00CVE-2026-16562
4.3
Medium
Shivamani VastralaYes
2026-08-03 00:00CVE-2026-15359
5.3
Medium
Shivamani VastralaYes
Showing 1–10 of 30 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C