tahu.datar

tahu.datar is a security researcher credited with 29 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #187 of 3,515 contributors. Their disclosures were published between 2024 and 2025. The most productive year was 2024, with 26 findings.

Their research concentrates on PHP Remote File Inclusion, which accounts for 26 of their findings (90%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, SQL Injection. The average CVSS score across these disclosures is 9.2, peaking at 9.8. Severity breakdown: 23 critical and 5 high.

The most affected software includes ABC APP CREATOR (1), ACH Invoicing Plugin (1), Checkout Mestres do WP for WooCommerce (1), across 29 distinct plugins, themes and core versions in total.

12 of the 29 disclosed issues have a vendor fix, while 17 remain unpatched. The most severe finding, "Grip <= 1.0.9 - Unauthenticated Local File Inclusion", scores 9.8 out of 10.

20242025
Critical
High
Medium
Low
Global Rank

#187

of 3,515 researchers

Vulns

29

Critical23
High5
Medium1
Low0
Affected Assets

29

24plugins5themes
Avg CVSS

9.2

Average score of vulnerabilities

Researcher Submissions

29 records
2025-04-14 00:00CVE-2025-26735
9.8
Critical
tahu.datarNo
2025-01-16 00:00CVE-2025-23422
8.1
High
tahu.datarNo
2025-01-03 00:00CVE-2025-22364
9.8
Critical
tahu.datarNo
2024-12-11 00:00CVE-2024-54380
9.8
Critical
tahu.datarNo
2024-12-11 00:00CVE-2024-54374
9.8
Critical
tahu.datarYes
2024-12-11 00:00CVE-2024-54375
9.8
Critical
tahu.datarNo
2024-12-02 00:00CVE-2024-53817
4.9
Medium
tahu.datarYes
2024-12-02 00:00CVE-2024-53811
7.2
High
tahu.datarYes
2024-11-18 00:00CVE-2024-52449
9.8
Critical
tahu.datarYes
2024-10-24 00:00CVE-2024-50434
9.8
Critical
tahu.datarYes
Showing 1–10 of 29 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C