Jakub Herman is a SOC Analyst and Threat Hunter based in Poland with a passion for vulnerability research. He has published 11 CVEs through Patchstack bug bounty program, with 39 more pending disclosure, and achieved #2 ranking on the platform. By day, he defends networks, by night, he hunts vulnerabilities in WordPress ecosystems.
[ENG] Hacking and securing WordPress plugins
I am a security researcher focused on finding vulnerabilities in Wordpress plugins. In just 3 months I have found 50 vulnerabilities, 11 cve’s and 39 awaiting diaclosure. I have acheved 2nd place in Patchstack March Leaderboard. I would like to deliver a talk mostly about broken authentication vulnerabilities in plugins, showing examples, real world impacts and remediations as well as use of AI in hunting and fixing vulnerabilities.
