WPscan

WPscan is a security researcher credited with 7 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #572 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 6 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 3 of their findings (43%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Hidden Functionality. The average CVSS score across these disclosures is 7.4, peaking at 9.8. Severity breakdown: 2 critical and 3 high.

The most affected software includes Quiz Maker (2), All in One SEO (1), Autoptimize (1), across 6 distinct plugins, themes and core versions in total.

6 of the 7 disclosed issues have a vendor fix, while 1 remain unpatched. The most severe finding, "Premium SEO - Malicious Plugin", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C