Offensive Security Researcher & Security Consultant

Supakiad S. (m3ez)

I find broken trust boundaries before attackers do.

Independent research and authorized assessments across web, identity, business logic, WordPress, and Microsoft products.

Research

Linked public evidence, grouped by scope. Each CVE ID opens its external advisory.

WordPress Plugin CVEs

2026

  • CVE-2026-32498RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.6 - Missing AuthorizationMedium (5.3) Source: Wordfence.
  • CVE-2026-32385RegistrationMagic <= 6.0.7.6 - Missing AuthorizationMedium (4.3) Source: Wordfence.
  • CVE-2026-23799Tutor LMS – eLearning and online course solution <= 3.9.5 - Missing AuthorizationMedium (4.3) Source: Wordfence.
  • CVE-2026-18352User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' ParameterHigh (7.5) Source: Wordfence.
  • CVE-2026-15981SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse ParameterCritical (9.8) Source: Wordfence.
  • CVE-2026-15022Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayMedium (6.5) Source: Wordfence.
  • CVE-2026-12761miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP FlowCritical (9.8) Source: Wordfence.
  • CVE-2026-7655SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated WebhookHigh (8.1) Source: Wordfence.
  • CVE-2026-7651User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' ParameterMedium (5.3) Source: Wordfence.
  • CVE-2026-7634SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent HeaderHigh (7.2) Source: Wordfence.
  • CVE-2026-4949ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan SubscriptionMedium (4.3) Source: Wordfence.
  • CVE-2026-4409Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription ManagementMedium (6.5) Source: Wordfence.
  • CVE-2026-4365LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer DeletionCritical (9.1) Source: Wordfence.
  • CVE-2026-4136Membership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirectMedium (4.3) Source: Wordfence.
  • CVE-2026-4109Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information ExposureMedium (4.3) Source: Wordfence.
  • CVE-2026-4058User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack CancellationMedium (4.3) Source: Wordfence.
  • CVE-2026-4021Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type ConfusionHigh (8.1) Source: Wordfence.
  • CVE-2026-3445Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment BypassHigh (7.1) Source: Wordfence.
  • CVE-2026-3360Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' ParameterHigh (7.5) Source: Wordfence.
  • CVE-2026-2936Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site ScriptingHigh (7.2) Source: Wordfence.
  • CVE-2026-2554WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User DeletionHigh (8.1) Source: Wordfence.
  • CVE-2026-2233User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' ParameterMedium (5.3) Source: Wordfence.
  • CVE-2026-2231Fluent Booking <= 2.0.01 - Unauthenticated Stored Cross-Site Scripting via Multiple ParametersHigh (7.2) Source: Wordfence.
  • CVE-2026-1869User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment BypassMedium (6.5) Source: Wordfence.
  • CVE-2026-1372Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin ActivationMedium (4.3) Source: Wordfence.
  • CVE-2026-1371Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX ActionMedium (5.3) Source: Wordfence.
  • CVE-2026-1238SlimStat Analytics <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via 'fh'High (7.2) Source: Wordfence.
  • CVE-2026-1065Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG fileHigh (7.2) Source: Wordfence.
  • CVE-2026-1058Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden FieldHigh (7.1) Source: Wordfence.
  • CVE-2026-0683SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field FilterMedium (6.5) Source: Wordfence.

2025

  • CVE-2025-47555Tutor LMS <= 3.9.4 - Authenticated (Instructor+) Insecure Direct Object ReferenceMedium (4.3) Source: Wordfence.
  • CVE-2025-15057SlimStat Analytics <= 5.3.3 - Unauthenticated Stored Cross-Site Scripting via 'fh' ParameterHigh (7.2) Source: Wordfence.
  • CVE-2025-15055SlimStat Analytics <= 5.3.4 - Unauthenticated Stored Cross-Site Scripting via 'notes/resource' ParametersHigh (7.2) Source: Wordfence.
  • CVE-2025-14151SlimStat Analytics <= 5.3.2 - Unauthenticated Stored Cross-Site ScriptingHigh (7.2) Source: Wordfence.
  • CVE-2025-13964LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course ModificationMedium (5.3) Source: Wordfence.
  • CVE-2025-13935Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course CompletionMedium (4.3) Source: Wordfence.
  • CVE-2025-13934Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment BypassMedium (4.3) Source: Wordfence.
  • CVE-2025-13679Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_detailsMedium (6.5) Source: Wordfence.
  • CVE-2025-13673Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_codeHigh (7.5) Source: Wordfence.
  • CVE-2025-13628Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon ModificationMedium (4.3) Source: Wordfence.
  • CVE-2025-12984Advanced Ads – Ad Manager & AdSense <= 2.0.15 - Authenticated (Admin+) SQL InjectionMedium (4.9) Source: Wordfence.
  • CVE-2025-12884Advanced Ads – Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+) Ad Placements UpdateMedium (4.3) Source: Wordfence.
  • CVE-2025-12814SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings ResetMedium (5.3) Source: Wordfence.

2024

  • CVE-2024-4367WordPress DearFlip Plugin <= 2.2.55 is vulnerable to Cross Site Scripting (XSS)Medium (6.5) Source: Patchstack.

Other CVEs

2025

  • CVE-2025-66307Grav Admin Plugin vulnerable to User Enumeration & Email DisclosureMedium (6.5) Source: GitHub Advisory.

Microsoft coordinated disclosures

Recognition

Public rankings and invitations.

2025
MSRC Most Valuable Researcher · #42Recognized among Microsoft’s 2025 Most Valuable Security Researchers.
2025 Q1
MSRC Security Researcher · #86Quarterly Microsoft Security Response Center leaderboard.
2024 Q3
MSRC overall #16 · Dynamics #6Overall and Microsoft Dynamics quarterly researcher rankings.
2024 Q1
MSRC Security Researcher · #32Quarterly Microsoft Security Response Center leaderboard.
2023
MSRC Most Valuable Researcher · #68Recognized among Microsoft’s 2023 Most Valuable Security Researchers.
2025 · 2026
Microsoft Zero Day Quest onsite inviteeInvited to Microsoft’s Redmond live-hacking event for two consecutive years.
Current
MSRC Special MentionListed by Microsoft Security Response Center; verified 2026-08-09.

Consulting

Authorized assessment work reduced to evidence and practical remediation.

Generalized capabilities only—no client identifiers or distinctive engagement fingerprints.

Authorization and workflow assessment
Authenticated workflows, APIs, identity, sessions, server-side role enforcement, and state transitions.
Output: Reproducible impact, risk classification, standards mapping, and remediation guidance.
Web and API attack-surface assessment
Request trust, data exposure, cross-origin behavior, component risk, and defensive configuration.
Output: A risk-ranked report with focused validation and retest evidence.
Enterprise application review
Authorization, session lifecycle, file handling, API exposure, identity integration, and configuration weaknesses.
Output: Source-to-impact evidence and practical fixes aligned with operational constraints.

Credentials

15 issuer-verified credentials and recognition badges.

Method

Map → trace → reproduce → document → verify

Contact

For authorized assessment, research collaboration, and speaking inquiries.

References