Offensive Security Researcher & Security Consultant
Supakiad S. (m3ez)
I find broken trust boundaries before attackers do.
Independent research and authorized assessments across web, identity, business logic, WordPress, and Microsoft products.
Research
Linked public evidence, grouped by scope. Each CVE ID opens its external advisory.
WordPress Plugin CVEs
2026
- CVE-2026-32498 — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.6 - Missing Authorization — Medium (5.3) Source: Wordfence.
- CVE-2026-32385 — RegistrationMagic <= 6.0.7.6 - Missing Authorization — Medium (4.3) Source: Wordfence.
- CVE-2026-23799 — Tutor LMS – eLearning and online course solution <= 3.9.5 - Missing Authorization — Medium (4.3) Source: Wordfence.
- CVE-2026-18352 — User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter — High (7.5) Source: Wordfence.
- CVE-2026-15981 — SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter — Critical (9.8) Source: Wordfence.
- CVE-2026-15022 — Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array — Medium (6.5) Source: Wordfence.
- CVE-2026-12761 — miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow — Critical (9.8) Source: Wordfence.
- CVE-2026-7655 — SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook — High (8.1) Source: Wordfence.
- CVE-2026-7651 — User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter — Medium (5.3) Source: Wordfence.
- CVE-2026-7634 — SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header — High (7.2) Source: Wordfence.
- CVE-2026-4949 — ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription — Medium (4.3) Source: Wordfence.
- CVE-2026-4409 — Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription Management — Medium (6.5) Source: Wordfence.
- CVE-2026-4365 — LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion — Critical (9.1) Source: Wordfence.
- CVE-2026-4136 — Membership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirect — Medium (4.3) Source: Wordfence.
- CVE-2026-4109 — Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure — Medium (4.3) Source: Wordfence.
- CVE-2026-4058 — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation — Medium (4.3) Source: Wordfence.
- CVE-2026-4021 — Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion — High (8.1) Source: Wordfence.
- CVE-2026-3445 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass — High (7.1) Source: Wordfence.
- CVE-2026-3360 — Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter — High (7.5) Source: Wordfence.
- CVE-2026-2936 — Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting — High (7.2) Source: Wordfence.
- CVE-2026-2554 — WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion — High (8.1) Source: Wordfence.
- CVE-2026-2233 — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter — Medium (5.3) Source: Wordfence.
- CVE-2026-2231 — Fluent Booking <= 2.0.01 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters — High (7.2) Source: Wordfence.
- CVE-2026-1869 — User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass — Medium (6.5) Source: Wordfence.
- CVE-2026-1372 — Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation — Medium (4.3) Source: Wordfence.
- CVE-2026-1371 — Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action — Medium (5.3) Source: Wordfence.
- CVE-2026-1238 — SlimStat Analytics <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via 'fh' — High (7.2) Source: Wordfence.
- CVE-2026-1065 — Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file — High (7.2) Source: Wordfence.
- CVE-2026-1058 — Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field — High (7.1) Source: Wordfence.
- CVE-2026-0683 — SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter — Medium (6.5) Source: Wordfence.
2025
- CVE-2025-47555 — Tutor LMS <= 3.9.4 - Authenticated (Instructor+) Insecure Direct Object Reference — Medium (4.3) Source: Wordfence.
- CVE-2025-15057 — SlimStat Analytics <= 5.3.3 - Unauthenticated Stored Cross-Site Scripting via 'fh' Parameter — High (7.2) Source: Wordfence.
- CVE-2025-15055 — SlimStat Analytics <= 5.3.4 - Unauthenticated Stored Cross-Site Scripting via 'notes/resource' Parameters — High (7.2) Source: Wordfence.
- CVE-2025-14151 — SlimStat Analytics <= 5.3.2 - Unauthenticated Stored Cross-Site Scripting — High (7.2) Source: Wordfence.
- CVE-2025-13964 — LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification — Medium (5.3) Source: Wordfence.
- CVE-2025-13935 — Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion — Medium (4.3) Source: Wordfence.
- CVE-2025-13934 — Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass — Medium (4.3) Source: Wordfence.
- CVE-2025-13679 — Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details — Medium (6.5) Source: Wordfence.
- CVE-2025-13673 — Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code — High (7.5) Source: Wordfence.
- CVE-2025-13628 — Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification — Medium (4.3) Source: Wordfence.
- CVE-2025-12984 — Advanced Ads – Ad Manager & AdSense <= 2.0.15 - Authenticated (Admin+) SQL Injection — Medium (4.9) Source: Wordfence.
- CVE-2025-12884 — Advanced Ads – Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+) Ad Placements Update — Medium (4.3) Source: Wordfence.
- CVE-2025-12814 — SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset — Medium (5.3) Source: Wordfence.
2024
- CVE-2024-4367 — WordPress DearFlip Plugin <= 2.2.55 is vulnerable to Cross Site Scripting (XSS) — Medium (6.5) Source: Patchstack.
Other CVEs
2025
- CVE-2025-66307 — Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure — Medium (6.5) Source: GitHub Advisory.
Microsoft coordinated disclosures
- Persistent XSS through indexed metadata
Externally controlled metadata reached an unsafe rendering sink through the indexing pipeline.
- DOM-based XSS through query
A search query crossed from URL input into an unsafe DOM rendering path.
- Reflected XSS through id
Untrusted form identifier data reached an HTML response without required output encoding.
- Reflected XSS through telemetryLocation
Telemetry location input crossed into a reflected browser-execution context.
Recognition
Public rankings and invitations.
- 2025
- MSRC Most Valuable Researcher · #42Recognized among Microsoft’s 2025 Most Valuable Security Researchers.
- 2025 Q1
- MSRC Security Researcher · #86Quarterly Microsoft Security Response Center leaderboard.
- 2024 Q3
- MSRC overall #16 · Dynamics #6Overall and Microsoft Dynamics quarterly researcher rankings.
- 2024 Q1
- MSRC Security Researcher · #32Quarterly Microsoft Security Response Center leaderboard.
- 2023
- MSRC Most Valuable Researcher · #68Recognized among Microsoft’s 2023 Most Valuable Security Researchers.
- 2025 · 2026
- Microsoft Zero Day Quest onsite inviteeInvited to Microsoft’s Redmond live-hacking event for two consecutive years.
- Current
- MSRC Special MentionListed by Microsoft Security Response Center; verified 2026-08-09.
Consulting
Authorized assessment work reduced to evidence and practical remediation.
Generalized capabilities only—no client identifiers or distinctive engagement fingerprints.
- Authorization and workflow assessment
- Authenticated workflows, APIs, identity, sessions, server-side role enforcement, and state transitions.
- Output: Reproducible impact, risk classification, standards mapping, and remediation guidance.
- Web and API attack-surface assessment
- Request trust, data exposure, cross-origin behavior, component risk, and defensive configuration.
- Output: A risk-ranked report with focused validation and retest evidence.
- Enterprise application review
- Authorization, session lifecycle, file handling, API exposure, identity integration, and configuration weaknesses.
- Output: Source-to-impact evidence and practical fixes aligned with operational constraints.
Credentials
15 issuer-verified credentials and recognition badges.
Method
Map → trace → reproduce → document → verify
Contact
For authorized assessment, research collaboration, and speaking inquiries.