siavashvafshar

siavashvafshar is a security researcher credited with 8 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #531 of 3,515 contributors. The disclosure was published in 2025.

Their research concentrates on Cross-Site Scripting, which accounts for 6 of their findings (75%). Other recurring categories include Improper Neutralization Of Script-Related HTML Tags In A Web Page (Basic XSS), Unrestricted Upload Of File With Dangerous Type. The average CVSS score across these disclosures is 6.4, peaking at 8.8. Severity breakdown: 0 critical and 1 high.

The most affected software includes Download Manager (1), Event Booking Manager for WooCommerce (1), Link Library (1), across 8 distinct plugins, themes and core versions in total.

6 of the 8 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Pixabay Images <= 3.4 - Authenticated (Author+) Arbitrary File Upload", scores 8.8 out of 10.

2025
Critical
High
Medium
Low
Global Rank

#531

of 3,515 researchers

Vulns

8

Critical0
High1
Medium7
Low0
Affected Assets

8

8plugins
Avg CVSS

6.4

Average score of vulnerabilities

Researcher Submissions

8 records
2025-06-17 14:04CVE-2025-4413
8.8
High
siavashvafsharNo
2025-06-06 21:50CVE-2025-5568
6.4
Medium
siavashvafsharYes
2025-05-16 00:00CVE-2025-48121
6.4
Medium
siavashvafsharNo
2025-04-30 18:14CVE-2025-3521
6.4
Medium
siavashvafsharYes
2025-04-17 19:29CVE-2025-3056
5.4
Medium
siavashvafsharYes
2025-04-08 15:42CVE-2025-3100
6.4
Medium
siavashvafsharYes
2025-04-07 00:00CVE-2025-2808
5.4
Medium
siavashvafsharYes
2025-04-04 11:06CVE-2025-2889
6.4
Medium
siavashvafsharYes
Showing 1–8 of 8 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C