vgo0

vgo0 is a security researcher credited with 249 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #34 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2024, with 188 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 209 of their findings (84%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization. The average CVSS score across these disclosures is 6.3, peaking at 9.9. Severity breakdown: 5 critical and 13 high.

The most affected software includes Affiliate Program Suite (2), HT Contact Form (2), Sky Addons for Elementor (2), across 246 distinct plugins, themes and core versions in total.

207 of the 249 disclosed issues have a vendor fix, while 42 remain unpatched. The most severe finding, "Tumult Hype Animations <= 1.9.15 - Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function", scores 9.9 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#34

of 3,515 researchers

Vulns

249

Critical5
High13
Medium231
Low0
Affected Assets

247

244plugins3themes
Avg CVSS

6.3

Average score of vulnerabilities

Researcher Submissions

249 records
2026-02-18 15:52CVE-2026-0912
8.8
High
vgo0Yes
2026-01-20 11:36CVE-2025-15521
9.8
Critical
vgo0Yes
2025-09-18 16:25CVE-2025-10146
6.1
Medium
vgo0Yes
2025-07-14 15:59CVE-2025-7340
9.8
Critical
vgo0Yes
2025-07-14 15:58CVE-2025-7341
9.1
Critical
vgo0Yes
2025-03-06 21:30CVE-2024-12634
6.1
Medium
vgo0Yes
2025-03-06 00:00CVE-2025-1309
8.8
High
vgo0Yes
2025-02-28 15:27CVE-2024-9212
6.1
Medium
vgo0Yes
2025-02-27 16:48CVE-2025-1511
6.1
Medium
vgo0Yes
2025-02-27 16:18CVE-2025-1505
6.1
Medium
vgo0Yes
Showing 1–10 of 249 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C