Sélim Lanouar (whattheslime)

Sélim Lanouar (whattheslime) is a security researcher credited with 5 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #727 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2026, with 2 findings.

Their research concentrates on Unrestricted Upload Of File With Dangerous Type, which accounts for 2 of their findings (40%). Other recurring categories include Incorrect Authorization, Missing Authorization. The average CVSS score across these disclosures is 7.8, peaking at 9.8. Severity breakdown: 2 critical and 1 high.

The most affected software includes File Away (2), All-in-One WP Migration Unlimited… (1), Ninja Forms - File Uploads (1), across 4 distinct plugins, themes and core versions in total.

3 of the 5 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload", scores 9.8 out of 10.

202420252026
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C