Truoc Phan

Truoc Phan is a security researcher credited with 49 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #122 of 3,515 contributors. Their disclosures were published between 2021 and 2026. The most productive year was 2023, with 19 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 22 of their findings (45%). Other recurring categories include Cross-Site Request Forgery (CSRF), Authentication Bypass Using An Alternate Path Or Channel. The average CVSS score across these disclosures is 6.8, peaking at 9.8. Severity breakdown: 10 critical and 7 high.

The most affected software includes MStore API (14), tagDiv Composer (11), Newspaper - News & WooCommerce… (3), across 20 distinct plugins, themes and core versions in total.

46 of the 49 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover", scores 9.8 out of 10.

202120222023202420252026
Critical
High
Medium
Low
Global Rank

#122

of 3,515 researchers

Vulns

49

Critical10
High7
Medium32
Low0
Affected Assets

21

14plugins7themes
Avg CVSS

6.8

Average score of vulnerabilities

Researcher Submissions

49 records
2026-08-24 15:27CVE-2026-12561
6.4
Medium
Truoc PhanNo
2025-05-07 00:00CVE-2025-2806
6.1
Medium
Truoc PhanYes
2025-04-29 19:47CVE-2025-2890
6.5
Medium
Truoc PhanYes
2025-03-27 19:53CVE-2025-1705
6.1
Medium
Truoc PhanYes
2025-03-27 16:33CVE-2025-2804
6.1
Medium
Truoc PhanYes
2024-10-01 00:00CVE-2024-7855
8.8
High
Truoc PhanYes
2024-08-30 00:00CVE-2024-3886
6.1
Medium
Truoc PhanYes
2024-08-30 00:00CVE-2024-5212
6.1
Medium
Truoc PhanYes
2024-08-16 00:00CVE-2023-3419
7.2
High
Truoc PhanYes
2024-08-16 00:00CVE-2023-3416
7.2
High
Truoc PhanYes
Showing 1–10 of 49 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C