Youssef Elouaer

Youssef Elouaer is a security researcher credited with 13 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #359 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Missing Authorization, which accounts for 5 of their findings (38%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Scripting. The average CVSS score across these disclosures is 6.5, peaking at 8.8. Severity breakdown: 0 critical and 6 high.

The most affected software includes Custom Block Builder (1), Gutena Forms (1), Kali Forms (1), across 13 distinct plugins, themes and core versions in total.

All 13 disclosed issues have since received a vendor fix. The most severe finding, "Custom Block Builder – Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution", scores 8.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#359

of 3,515 researchers

Vulns

13

Critical0
High6
Medium7
Low0
Affected Assets

13

13plugins
Avg CVSS

6.5

Average score of vulnerabilities

Researcher Submissions

13 records
2026-04-08 00:00CVE-2026-2519
5.3
Medium
Youssef ElouaerYes
2026-04-07 00:00CVE-2026-3396
7.5
High
Youssef ElouaerYes
2026-04-03 13:05CVE-2026-3571
6.5
Medium
Youssef ElouaerYes
2026-03-23 16:11CVE-2026-3138
6.5
Medium
Youssef ElouaerYes
2026-03-14 13:14CVE-2026-1947
7.5
High
Youssef ElouaerYes
2026-03-14 13:11CVE-2026-1883
4.3
Medium
Youssef ElouaerYes
2026-03-14 00:34CVE-2026-1870
5.3
Medium
Youssef ElouaerYes
2026-03-10 00:00CVE-2026-3178
7.2
High
Youssef ElouaerYes
2026-03-10 00:00CVE-2026-1454
7.2
High
Youssef ElouaerYes
2026-03-03 21:42CVE-2026-1674
6.5
Medium
Youssef ElouaerYes
Showing 1–10 of 13 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C