701
All Time Ranking
5
All Time Discoveries
3
90 Day Published Submissions
21 Aug '26
Last Published Submission

About

Raihan Adi Arba is a young cybersecurity enthusiast from Central Java, Indonesia, currently pursuing a Bachelor's degree in Informatics Engineering at Telkom University. Despite his age, he has built an impressive track record as a penetration tester, most notably reaching Rank #1 on the Dropbox Bug Bounty Leaderboard in Q3 2025 and earning recognition from platforms like Nutaku, ClassDojo, and Aiven.

Submitted 1 Vulnerability
Submitted 1 Vulnerability
August 14, 2026

5 Vulnerabilities

Title CVE ID CVSS Vector Date
User Registration <= 5.1.5 - Reflected Cross-Site Scripting CVE-2026-42652 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 9, 2026
Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action CVE-2026-8840 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 14, 2026
Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.41 - Missing Authorization CVE-2026-42675 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N May 15, 2026
Greenshift <= 12.8.9 - Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings' CVE-2026-5093 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N August 21, 2026
Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter CVE-2026-12905 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N August 15, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation