Valatty

Valatty is a security researcher credited with 7 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #596 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 5 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 2 of their findings (29%). Other recurring categories include External Control Of Assumed-Immutable Web Parameter, Improper Verification Of Cryptographic Signature. The average CVSS score across these disclosures is 6.3, peaking at 7.5. Severity breakdown: 0 critical and 2 high.

The most affected software includes CorvusPay WooCommerce Payment Gateway (3), Click to Chat (1), MinimogWP (1), across 5 distinct plugins, themes and core versions in total.

All 7 disclosed issues have since received a vendor fix.

20252026
Critical
High
Medium
Low
Global Rank

#596

of 3,515 researchers

Vulns

7

Critical0
High2
Medium5
Low0
Affected Assets

5

4plugins1theme
Avg CVSS

6.3

Average score of vulnerabilities

Researcher Submissions

7 records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C