Tonn
Tonn is a security researcher credited with 87 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #79 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 58 findings.
Their research concentrates on Authentication Bypass Using An Alternate Path Or Channel, which accounts for 16 of their findings (18%). Other recurring categories include Improper Privilege Management, Path Traversal. The average CVSS score across these disclosures is 9.1, peaking at 10.0. Severity breakdown: 47 critical and 36 high.
The most affected software includes WP JobHunt (4), AdForest (3), JobSearch WP Job Board (3), across 69 distinct plugins, themes and core versions in total.
71 of the 87 disclosed issues have a vendor fix, while 16 remain unpatched. The most severe finding, "WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload", scores 10.0 out of 10.
#79
of 3,515 researchers
87
69
9.1
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C