Usama Arshad

Usama Arshad is a security researcher credited with 16 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #321 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2026, with 15 findings.

Their research concentrates on Authorization Bypass Through User-Controlled Key, which accounts for 5 of their findings (31%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Missing Authorization. The average CVSS score across these disclosures is 5.2, peaking at 6.4.

The most affected software includes Project Manager (2), WC Vendors (2), Accept Stripe Payments (1), across 14 distinct plugins, themes and core versions in total.

All 16 disclosed issues have since received a vendor fix.

202420252026
Critical
High
Medium
Low
Global Rank

#321

of 3,515 researchers

Vulns

16

Critical0
High0
Medium16
Low0
Affected Assets

14

14plugins
Avg CVSS

5.2

Average score of vulnerabilities

Researcher Submissions

16 records
2026-09-03 00:00CVE-2026-81423
6.1
Medium
Usama ArshadYes
2026-09-02 00:00CVE-2026-16281
4.3
Medium
Usama ArshadYes
2026-09-02 00:00CVE-2026-81428
4.3
Medium
Usama ArshadYes
2026-09-02 00:00CVE-2026-81426
4.3
Medium
Usama ArshadYes
2026-08-31 00:00CVE-2026-77788
4.3
Medium
Usama ArshadYes
2026-08-26 00:00CVE-2026-74930
4.3
Medium
Usama ArshadYes
2026-08-24 00:00CVE-2026-74928
5.3
Medium
Usama ArshadYes
2026-08-24 00:00CVE-2026-16575
5.3
Medium
Usama ArshadYes
2026-08-10 00:00CVE-2026-16737
5.3
Medium
Usama ArshadYes
2026-08-10 00:00CVE-2026-18789
5.3
Medium
Usama ArshadYes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C