theviper17

theviper17 is a security researcher credited with 20 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #257 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2026, with 18 findings.

Their research concentrates on Missing Authorization, which accounts for 8 of their findings (40%). Other recurring categories include Cross-Site Scripting, Exposure Of Sensitive Information To An Unauthorized Actor. The average CVSS score across these disclosures is 5.3, peaking at 7.2. Severity breakdown: 0 critical and 1 high.

The most affected software includes Bold Page Builder (1), Email Inquiry & Cart Options… (1), Extend Link (1), across 20 distinct plugins, themes and core versions in total.

15 of the 20 disclosed issues have a vendor fix, while 5 remain unpatched.

202420252026
Critical
High
Medium
Low
Global Rank

#257

of 3,515 researchers

Vulns

20

Critical0
High1
Medium19
Low0
Affected Assets

20

20plugins
Avg CVSS

5.3

Average score of vulnerabilities

Researcher Submissions

20 records
2026-09-02 00:00CVE-2026-81776
7.2
High
theviper17No
2026-06-23 00:00CVE-2026-56026
6.4
Medium
theviper17Yes
2026-06-12 00:00CVE-2026-24618
4.3
Medium
theviper17Yes
2026-05-25 00:00CVE-2026-24554
4.3
Medium
theviper17Yes
2026-03-23 00:00CVE-2026-25398
4.3
Medium
theviper17Yes
2026-03-17 00:00CVE-2026-25455
4.3
Medium
theviper17Yes
2026-03-05 00:00CVE-2026-22491
6.1
Medium
theviper17No
2026-01-26 00:00CVE-2026-24528
6.4
Medium
theviper17Yes
2026-01-26 00:00CVE-2026-24526
6.4
Medium
theviper17No
2026-01-25 00:00CVE-2026-25432
6.4
Medium
theviper17No
Showing 1–10 of 20 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C