Skip to content
View Aryoksss's full-sized avatar

Block or report Aryoksss

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Aryoksss/README.md

sorawautsukushiii

Security Researcher · Bug Bounty Hunter · CTF Player

   

profile views

About

Security researcher focused on WordPress plugin vulnerabilities for the Wordfence Bug Bounty Program. I hunt for privilege escalation, arbitrary file upload/read/delete, authentication bypass, and RCE in WordPress plugins.

  • 🐛  Reported vulnerabilities via Wordfence Bug Bounty
  • 🏴  CTF player (Web Exploit)
  • ✍️  Writing security writeups at blog.aryok.tech

CVEs

CVE ID Plugin Vulnerability Severity
CVE-2026-9018 Easy Elements for Elementor (≤ 1.4.9) Unauthenticated Privilege Escalation via custom_meta 🟠 High (8.8)
CVE-2026-8095 Frontend File Manager Plugin (≤ 23.6) Authenticated (Subscriber+) Arbitrary File Deletion 🟠 High (8.1)

TryHackMe

TryHackMe Badge

Pinned Loading

  1. wp-hunter wp-hunter Public

    WP Hunter is a bilingual command-line toolkit for collecting WordPress.org and Patchstack VDP targets, downloading verified plugin archives, and running fail-safe Semgrep triage.

    Python 1