Security Researcher · Bug Bounty Hunter · CTF Player
Security researcher focused on WordPress plugin vulnerabilities for the Wordfence Bug Bounty Program. I hunt for privilege escalation, arbitrary file upload/read/delete, authentication bypass, and RCE in WordPress plugins.
- 🐛 Reported vulnerabilities via Wordfence Bug Bounty
- 🏴 CTF player (Web Exploit)
- ✍️ Writing security writeups at blog.aryok.tech
| CVE ID | Plugin | Vulnerability | Severity |
|---|---|---|---|
| CVE-2026-9018 | Easy Elements for Elementor (≤ 1.4.9) | Unauthenticated Privilege Escalation via custom_meta |
🟠 High (8.8) |
| CVE-2026-8095 | Frontend File Manager Plugin (≤ 23.6) | Authenticated (Subscriber+) Arbitrary File Deletion | 🟠 High (8.1) |


