YC_Infosec

YC_Infosec is a security researcher credited with 17 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #289 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2024, with 9 findings.

Their research concentrates on SQL Injection, which accounts for 5 of their findings (29%). Other recurring categories include PHP Remote File Inclusion, Path Traversal. The average CVSS score across these disclosures is 7.6, peaking at 10.0. Severity breakdown: 5 critical and 5 high.

The most affected software includes Booking for Appointments and Events… (1), BuddyPress Cover (1), Compute Links (1), across 17 distinct plugins, themes and core versions in total.

10 of the 17 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "BuddyPress Cover <= 2.1.4.2 - Unauthenticated Arbitrary File Upload", scores 10.0 out of 10.

202420252026
Critical
High
Medium
Low
Global Rank

#289

of 3,515 researchers

Vulns

17

Critical5
High5
Medium7
Low0
Affected Assets

17

17plugins
Avg CVSS

7.6

Average score of vulnerabilities

Researcher Submissions

17 records
2026-02-04 11:20CVE-2025-13192
8.2
High
YC_InfosecYes
2025-12-11 15:08CVE-2025-13320
6.8
Medium
YC_InfosecYes
2025-12-03 00:27CVE-2025-13342
9.8
Critical
YC_InfosecYes
2025-12-01 11:27CVE-2025-12529
8.8
High
YC_InfosecYes
2025-11-15 15:54CVE-2025-12482
7.5
High
YC_InfosecYes
2025-10-31 00:00CVE-2025-11740
6.5
Medium
YC_InfosecYes
2025-10-23 00:00CVE-2025-64366
6.5
Medium
YC_InfosecYes
2025-09-09 00:00CVE-2025-58993
4.9
Medium
YC_InfosecYes
2024-08-12 00:00CVE-2024-43261
9.8
Critical
YC_InfosecNo
2024-06-18 00:00CVE-2024-35767
9.1
Critical
YC_InfosecYes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C