Sushi Com Abacate

Sushi Com Abacate is a security researcher credited with 8 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #546 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 4 findings.

Their research concentrates on Missing Authorization, which accounts for 5 of their findings (63%). Other recurring categories include Server-Side Request Forgery (SSRF), PHP Remote File Inclusion. The average CVSS score across these disclosures is 6.0, peaking at 9.8. Severity breakdown: 1 critical and 0 high.

The most affected software includes Canto (1), Carousel Block (1), Eventin (1), across 8 distinct plugins, themes and core versions in total.

All 8 disclosed issues have since received a vendor fix. The most severe finding, "Canto <= 3.0.8 - Unauthenticated Remote File Inclusion", scores 9.8 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#546

of 3,515 researchers

Vulns

8

Critical1
High0
Medium7
Low0
Affected Assets

8

8plugins
Avg CVSS

6.0

Average score of vulnerabilities

Researcher Submissions

8 records
2026-09-08 16:23CVE-2026-11821
5.4
Medium
Sushi Com AbacateYes
2026-07-09 14:47CVE-2026-11818
5.4
Medium
Sushi Com AbacateYes
2026-02-18 00:00CVE-2025-14864
4.3
Medium
Sushi Com AbacateYes
2025-11-18 01:11CVE-2025-12376
6.4
Medium
Sushi Com AbacateYes
2025-11-04 17:38CVE-2025-12388
6.4
Medium
Sushi Com AbacateYes
2025-08-01 18:48CVE-2025-8152
5.3
Medium
Sushi Com AbacateYes
2025-05-20 20:31CVE-2025-4105
5.4
Medium
Sushi Com AbacateYes
2024-06-13 15:59CVE-2024-4936
9.8
Critical
Sushi Com AbacateYes
Showing 1–8 of 8 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C