Yorick Koster,

Yorick Koster, is a security researcher credited with 36 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #162 of 3,515 contributors. Their disclosures were published between 2016 and 2018. The most productive year was 2016, with 26 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 21 of their findings (58%). Other recurring categories include Deserialization Of Untrusted Data, Cross-Site Request Forgery (CSRF). The average CVSS score across these disclosures is 7.3, peaking at 9.8. Severity breakdown: 5 critical and 12 high.

The most affected software includes Google Forms (2), WordPress 4.7 (2), Activity Log (1), across 34 distinct plugins, themes and core versions in total.

33 of the 36 disclosed issues have a vendor fix, while 3 remain unpatched. The most severe finding, "Analytics Stats Counter Statistics <= 1.2.2.5 - Unauthenticated PHP Object Injection", scores 9.8 out of 10.

201620172018
Critical
High
Medium
Low
Global Rank

#162

of 3,515 researchers

Vulns

36

Critical5
High12
Medium19
Low0
Affected Assets

34

31plugins1theme2core versions
Avg CVSS

7.3

Average score of vulnerabilities

Researcher Submissions

36 records
2018-03-02 00:00CVE-2017-18613
6.1
Medium
Yorick Koster,Yes
2017-05-16 00:00CVE-2017-9064
8.8
High
Yorick Koster,Yes
2017-03-17 00:00N/A
8.3
High
Yorick Koster,Yes
2017-03-06 00:00CVE-2017-6814
6.4
Medium
Chris Andrè DaleYes
2017-03-01 00:00CVE-2017-20090
8.8
High
Yorick Koster,No
2017-03-01 00:00N/A
6.1
Medium
Yorick Koster,Yes
2017-03-01 00:00N/A
6.1
Medium
Yorick Koster,No
2017-03-01 00:00N/A
9.8
Critical
Yorick Koster,No
2017-01-25 00:00CVE-2016-15004
9.8
Critical
Yorick Koster,Yes
2017-01-07 00:00N/A
9.8
Critical
Yorick Koster,Yes
Showing 1–10 of 36 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C