vgo0
vgo0 is a security researcher credited with 249 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #34 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2024, with 188 findings.
Their research concentrates on Cross-Site Scripting, which accounts for 209 of their findings (84%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization. The average CVSS score across these disclosures is 6.3, peaking at 9.9. Severity breakdown: 5 critical and 13 high.
The most affected software includes Affiliate Program Suite (2), HT Contact Form (2), Sky Addons for Elementor (2), across 246 distinct plugins, themes and core versions in total.
207 of the 249 disclosed issues have a vendor fix, while 42 remain unpatched. The most severe finding, "Tumult Hype Animations <= 1.9.15 - Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function", scores 9.9 out of 10.
#34
of 3,515 researchers
249
247
6.3
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C