YC_Infosec
YC_Infosec is a security researcher credited with 17 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #289 of 3,515 contributors. Their disclosures were published between 2024 and 2026. The most productive year was 2024, with 9 findings.
Their research concentrates on SQL Injection, which accounts for 5 of their findings (29%). Other recurring categories include PHP Remote File Inclusion, Path Traversal. The average CVSS score across these disclosures is 7.6, peaking at 10.0. Severity breakdown: 5 critical and 5 high.
The most affected software includes Booking for Appointments and Events… (1), BuddyPress Cover (1), Compute Links (1), across 17 distinct plugins, themes and core versions in total.
10 of the 17 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "BuddyPress Cover <= 2.1.4.2 - Unauthenticated Arbitrary File Upload", scores 10.0 out of 10.
#289
of 3,515 researchers
17
17
7.6
Average score of vulnerabilities
Researcher Submissions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C