Veshraj Ghimire

Veshraj Ghimire is a security researcher credited with 17 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #291 of 3,515 contributors. Their disclosures were published between 2021 and 2025. The most productive year was 2022, with 12 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 8 of their findings (47%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Missing Authorization. The average CVSS score across these disclosures is 5.7, peaking at 7.1. Severity breakdown: 0 critical and 1 high.

The most affected software includes WPQA - Builder forms Addon For WordPress (4), Sensei LMS (2), Workreap - Freelance Marketplace… (2), across 12 distinct plugins, themes and core versions in total.

14 of the 17 disclosed issues have a vendor fix, while 3 remain unpatched.

20212022202320242025
Critical
High
Medium
Low
Global Rank

#291

of 3,515 researchers

Vulns

17

Critical0
High1
Medium16
Low0
Affected Assets

12

8plugins4themes
Avg CVSS

5.7

Average score of vulnerabilities

Researcher Submissions

17 records
2025-03-05 00:00CVE-2024-13146
4.3
Medium
Veshraj GhimireYes
2023-01-30 00:00CVE-2023-0453
7.1
High
Veshraj GhimireYes
2022-12-09 00:00CVE-2022-4114
6.4
Medium
Veshraj GhimireYes
2022-12-02 00:00CVE-2022-4239
5.4
Medium
Veshraj GhimireYes
2022-11-12 00:00CVE-2022-3846
5.4
Medium
Veshraj GhimireYes
2022-09-13 00:00CVE-2022-3194
5.5
Medium
Veshraj GhimireYes
2022-08-04 00:00CVE-2022-2080
4.3
Medium
Veshraj GhimireYes
2022-08-04 00:00CVE-2022-2034
5.3
Medium
Veshraj GhimireYes
2022-07-12 00:00CVE-2022-1323
6.3
Medium
Veshraj GhimireYes
2022-05-16 00:00CVE-2022-1241
6.1
Medium
Veshraj GhimireYes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C