Valatty
Valatty is a security researcher credited with 7 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #596 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 5 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 2 of their findings (29%). Other recurring categories include External Control Of Assumed-Immutable Web Parameter, Improper Verification Of Cryptographic Signature. The average CVSS score across these disclosures is 6.3, peaking at 7.5. Severity breakdown: 0 critical and 2 high.
The most affected software includes CorvusPay WooCommerce Payment Gateway (3), Click to Chat (1), MinimogWP (1), across 5 distinct plugins, themes and core versions in total.
All 7 disclosed issues have since received a vendor fix.
#596
of 3,515 researchers
7
5
6.3
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C