I’m a cybersecurity researcher passionate about improving security at scale through automation, offensive testing, and clear reporting.
I focus on turning complex issues into practical solutions that help organizations strengthen their defenses.
Focus areas: Web security · Recon automation · Vulnerability assessment · Secure development practices · Responsible disclosure · Security tooling
Over time, I’ve collaborate with different organizations by reporting security issues and being recognized in their acknowledgements and halls of fame. Here are some of them:
![]() NASA Security Acknowledgement |
![]() Educación Madrid Hall of Fame |
Wordfence Researcher Profile |
Highlights of companies that trusted my research and credited my findings.
+20 published CVEs · Mostly Web / WordPress security research
| Highlight | CVE | CVSS | Date |
|---|---|---|---|
| Migration, Backup, Staging <= 0.9.123 — Unauthenticated Arbitrary File Upload | CVE-2026-1357 | 9.8 | February 10, 2026 |
| Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 — Unauthenticated Sensitive Information Exposure | CVE-2025-11723 | 6.5 | January 5, 2026 |
| Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 — IDOR to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token | CVE-2025-11924 | 7.5 | December 16, 2025 |
| RSS Aggregator by Feedzy <= 5.1.1 — Unauthenticated Blind Server-Side Request Forgery | CVE-2025-11467 | 5.8 | December 10, 2025 |
| LearnPress – WordPress LMS Plugin <= 4.2.9.4 — Unauthenticated Arbitrary Callback Execution to Information Exposure | CVE-2025-11368 | 5.3 | November 20, 2025 |
| LearnPress – WordPress LMS Plugin <= 4.2.9.3 — Unauthenticated Database Table Manipulation | CVE-2025-11372 | 6.5 | October 17, 2025 |
| Media Library Assistant <= 3.29 — Unauthenticated Limited File Read | CVE-2025-11738 | 5.3 | October 17, 2025 |
| Elementinvader Addons for Elementor <= 1.4.0 — Unauthenticated Arbitrary Email Sending | CVE-2025-10873 | 5.8 | October 15, 2025 |
| Quick Featured Images <= 13.7.2 — Insecure Direct Object Reference to Image Manipulation | CVE-2025-11176 | 4.3 | October 14, 2025 |
Full list: Wordfence researcher page → https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lucas-montes
Every 500 Internal Server Error hides a secret.
Last updated: 11/02/2026

