SOPROBRO

SOPROBRO is a security researcher credited with 824 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #3 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 413 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 500 of their findings (61%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization. The average CVSS score across these disclosures is 6.2, peaking at 9.8. Severity breakdown: 1 critical and 12 high.

The most affected software includes Annie (2), Apply with LinkedIn buttons (2), Ebook Downloader (2), across 811 distinct plugins, themes and core versions in total.

181 of the 824 disclosed issues have a vendor fix, while 643 remain unpatched. The most severe finding, "Computer Repair Shop <= 3.8119 - Authenticated (Customer+) Privilege Esclation via Account Takeover", scores 9.8 out of 10.

20242025
Critical
High
Medium
Low
Global Rank

#3

of 3,515 researchers

Vulns

824

Critical1
High12
Medium811
Low0
Affected Assets

812

812plugins
Avg CVSS

6.2

Average score of vulnerabilities

Researcher Submissions

824 records
2025-04-17 00:00CVE-2025-39455
4.3
Medium
SOPROBROYes
2025-04-14 00:00CVE-2025-32561
6.1
Medium
SOPROBRONo
2025-04-10 00:00CVE-2025-32516
6.1
Medium
SOPROBROYes
2025-04-09 00:00CVE-2025-32518
6.1
Medium
SOPROBROYes
2025-04-09 00:00CVE-2025-32505
6.1
Medium
SOPROBRONo
2025-04-09 00:00CVE-2025-32503
4.4
Medium
SOPROBRONo
2025-04-09 00:00CVE-2025-32555
6.1
Medium
SOPROBRONo
2025-04-09 00:00CVE-2025-32502
6.1
Medium
SOPROBRONo
2025-04-09 00:00CVE-2025-32500
6.1
Medium
SOPROBRONo
2025-04-09 00:00CVE-2025-32563
6.1
Medium
SOPROBRONo
Showing 1–10 of 250 reports

Showing the 250 most recent of 824 records. Every record has its own page and is listed in the sitemap.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C