timomangcut
timomangcut is a security researcher credited with 74 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #89 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2025, with 41 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 26 of their findings (35%). Other recurring categories include SQL Injection, Missing Authorization. The average CVSS score across these disclosures is 6.4, peaking at 9.8. Severity breakdown: 5 critical and 14 high.
The most affected software includes Fable Extra (2), Flickr set slideshows (2), Include URL (2), across 69 distinct plugins, themes and core versions in total.
56 of the 74 disclosed issues have a vendor fix, while 18 remain unpatched. The most severe finding, "Pix 4x sem juros - Pagaleve <= 1.6.9 - Unauthenticated PHP Object Injection", scores 9.8 out of 10.
#89
of 3,515 researchers
74
69
6.4
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C