I focus on identifying security issues in web applications and reporting them directly to site owners in a responsible and non-disruptive manner.
My work is focused on manual web application testing with an emphasis on access control issues, input validation flaws, and business logic problems. I follow responsible disclosure practices and do not publish sensitive details without permission.
Publicly verifiable reports, tracked via the Wordfence Threat Intelligence and Patchstack Vulnerability Disclosure Programs. Severity shown as reported by each source (WF / PS).
| Plugin | Vulnerability | Severity (WF / PS) | Status |
|---|---|---|---|
| APIExperts Square for WooCommerce | Authenticated (Subscriber+) SQL Injection · CVE-2026-57810 | 6.5 / 8.5 | Patched |
| Digital Signature Add-on for WooCommerce | Unauthenticated Information Exposure · CVE-2026-52694 | 5.3 / 7.5 | Patched |
| Knit Pay | Missing Authorization · CVE-2026-49070 | 5.3 / 7.5 | Patched |
| Autopay dla WooCommerce | Missing Authorization · CVE-2026-57425 | 5.3 / 6.5 | Patched |
| Booking and Rental Manager | Missing Authorization · CVE-2026-57660 | 5.3 / 5.3 | Patched |
| Nelio Content | Missing Authorization · CVE-2026-57648 | 4.3 / 4.3 | Patched |
| Content Views – Post Grid & Filter | Missing Authorization · CVE-2026-15179 | 5.3 | Disclosed |
| Team Members | Stored XSS (Administrator+) · CVE-2026-12114 | 4.4 | Resolved |
| Autoship Cloud for WooCommerce | Broken Access Control | 6.5 | Validated |
Full list with disclosure dates and technical detail available on my Patchstack profile and Wordfence profile.
Explore detailed security case studies and technical write-ups demonstrating real-world vulnerability research and responsible disclosure.
View Full Portfolio →