Tonn

Tonn is a security researcher credited with 87 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #79 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2025, with 58 findings.

Their research concentrates on Authentication Bypass Using An Alternate Path Or Channel, which accounts for 16 of their findings (18%). Other recurring categories include Improper Privilege Management, Path Traversal. The average CVSS score across these disclosures is 9.1, peaking at 10.0. Severity breakdown: 47 critical and 36 high.

The most affected software includes WP JobHunt (4), AdForest (3), JobSearch WP Job Board (3), across 69 distinct plugins, themes and core versions in total.

71 of the 87 disclosed issues have a vendor fix, while 16 remain unpatched. The most severe finding, "WP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File Upload", scores 10.0 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#79

of 3,515 researchers

Vulns

87

Critical47
High36
Medium4
Low0
Affected Assets

69

59plugins10themes
Avg CVSS

9.1

Average score of vulnerabilities

Researcher Submissions

87 records
2026-09-04 00:00CVE-2025-9049
8.8
High
TonnYes
2025-11-24 14:03CVE-2025-6389
9.8
Critical
TonnYes
2025-10-30 18:34CVE-2025-7846
8.8
High
TonnYes
2025-10-30 00:00CVE-2025-8385
6.8
Medium
TonnYes
2025-10-23 00:00CVE-2025-6440
9.8
Critical
TonnNo
2025-10-10 20:34CVE-2025-6439
9.8
Critical
TonnNo
2025-10-02 19:26CVE-2025-6388
9.8
Critical
TonnYes
2025-09-05 00:00CVE-2025-8359
9.8
Critical
TonnYes
2025-08-25 19:03CVE-2025-6366
8.8
High
TonnYes
2025-07-28 16:22CVE-2025-3075
6.4
Medium
TonnYes
Showing 1–10 of 87 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C