sterva

sterva is a security researcher credited with 7 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #591 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 5 findings.

Their research concentrates on Path Traversal, which accounts for 2 of their findings (29%). Other recurring categories include Code Injection, Cross-Site Scripting. The average CVSS score across these disclosures is 6.3, peaking at 7.2. Severity breakdown: 0 critical and 4 high.

The most affected software includes Database Backup and Table Integrity… (3), CURCY (1), LTL Freight Quotes (1), across 5 distinct plugins, themes and core versions in total.

All 7 disclosed issues have since received a vendor fix.

202420252026
Critical
High
Medium
Low
Global Rank

#591

of 3,515 researchers

Vulns

7

Critical0
High4
Medium3
Low0
Affected Assets

7

7plugins
Avg CVSS

6.3

Average score of vulnerabilities

Researcher Submissions

7 records
2026-07-02 00:00CVE-2026-11778
5.4
Medium
stervaYes
2025-06-06 20:22CVE-2025-5303
7.2
High
stervaYes
2025-03-25 00:00CVE-2025-2257
7.2
High
stervaYes
2025-03-12 00:00CVE-2025-2250
4.9
Medium
stervaYes
2025-02-28 00:00CVE-2024-13911
7.2
High
stervaYes
2025-02-28 00:00CVE-2024-13910
7.2
High
stervaYes
2024-12-23 21:07CVE-2024-12850
4.9
Medium
stervaYes
Showing 1–7 of 7 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C