Skip to content
View LucasM0ntes's full-sized avatar
  • España

Block or report LucasM0ntes

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
LucasM0ntes/README.md

Offensive Security – Penetration Tester

Hall of Fame researcher · Bug Bounty Hunter

Wordfence GitHub


👋 About me

I’m a cybersecurity researcher passionate about improving security at scale through automation, offensive testing, and clear reporting.
I focus on turning complex issues into practical solutions that help organizations strengthen their defenses.

Focus areas: Web security · Recon automation · Vulnerability assessment · Secure development practices · Responsible disclosure · Security tooling


🏆 Hall of Fame

Over time, I’ve collaborate with different organizations by reporting security issues and being recognized in their acknowledgements and halls of fame. Here are some of them:

NASA
NASA
Security Acknowledgement
Educación Madrid
Educación Madrid
Hall of Fame
Wordfence
Wordfence
Researcher Profile

Highlights of companies that trusted my research and credited my findings.


💥 Best CVEs

+20 published CVEs · Mostly Web / WordPress security research

Highlight CVE CVSS Date
Migration, Backup, Staging <= 0.9.123 — Unauthenticated Arbitrary File Upload CVE-2026-1357 9.8 February 10, 2026
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 — Unauthenticated Sensitive Information Exposure CVE-2025-11723 6.5 January 5, 2026
Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 — IDOR to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token CVE-2025-11924 7.5 December 16, 2025
RSS Aggregator by Feedzy <= 5.1.1 — Unauthenticated Blind Server-Side Request Forgery CVE-2025-11467 5.8 December 10, 2025
LearnPress – WordPress LMS Plugin <= 4.2.9.4 — Unauthenticated Arbitrary Callback Execution to Information Exposure CVE-2025-11368 5.3 November 20, 2025
LearnPress – WordPress LMS Plugin <= 4.2.9.3 — Unauthenticated Database Table Manipulation CVE-2025-11372 6.5 October 17, 2025
Media Library Assistant <= 3.29 — Unauthenticated Limited File Read CVE-2025-11738 5.3 October 17, 2025
Elementinvader Addons for Elementor <= 1.4.0 — Unauthenticated Arbitrary Email Sending CVE-2025-10873 5.8 October 15, 2025
Quick Featured Images <= 13.7.2 — Insecure Direct Object Reference to Image Manipulation CVE-2025-11176 4.3 October 14, 2025

Full list: Wordfence researcher page → https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lucas-montes


PentesterLab 7 Badges All PortSwigger labs completed

Every 500 Internal Server Error hides a secret.
Last updated: 11/02/2026

@LucasM0ntes's activity is private