GreenHat Vulnerability Research Program

Finding flaws. Coordinating fixes. Sharing what defenders need.

GreenHat researchers investigate real-world software in authorized environments, privately report verified vulnerabilities, and publish clear defensive guidance after coordinated disclosure.

This is a living archive: researcher profiles, software groups, and public counts are generated from the published records, keeping attribution and remediation context connected as the program expands. No placeholder findings are published.

Authorization first. This is a public research archive, not an invitation to test systems.

Published CVE
1
Software project
1
Researcher credited
1
Documented fix
1

Public records as of August 10, 2026

Findings grouped by the software they affect

Every public record connects the affected product, credited researcher, vulnerability class, remediation status, and primary sources. As the archive grows, new CVEs stay grouped with the software where defenders need them.

1 software project · 1 published finding

WordPress · Management and monitoring plugin

WP Umbrella

WP Umbrella is a WordPress management and monitoring platform. The first published GreenHat research record affects its WordPress plugin.

First GreenHat public CVE record

CVE-2026-66642

Cross-site request forgery in the WP Umbrella WordPress plugin

PatchedCVSS 3.1 · 5.4 Medium

The published record identifies a cross-site request forgery vulnerability affecting WP Umbrella versions 2.24.2 through 2.26.2. The vendor explains that exploitation required a logged-in WordPress administrator to visit a malicious page.

Disclosure timeline

  1. Reported to Patchstack

    Anthony Green's report entered Patchstack's managed disclosure process.

  2. Vendor independently finds and fixes the issue

    WP Umbrella says its internal audit separately found and fixed the issue before the report reached its team.

  3. Patch and CVE published

    WP Umbrella 2.27.0 and the coordinated public CVE record were released.

The vendor describes its internal discovery as independent of the external report. The official CVE record credits Anthony Green [Antnation] as the finder.

Update guidance

Update WP Umbrella to version 2.27.0 or later.

What defenders can carry forward

Security checks should validate the route the application resolved, rather than trusting a matching string found elsewhere in the raw request URL.

Credit the people behind every finding

The directory grows with the program. Each researcher profile is connected to the software and CVEs on which that person is publicly credited—without invented rankings or placeholder achievements.

Illustrated avatar of Anthony Green, known as antnation

Researcher 01

Anthony Green

@antnation

Founder, GreenHat Security · Security Researcher

Anthony is the GreenHat researcher credited on CVE-2026-66642. Find him under the handle antnation on Patchstack, Intigriti, HackerOne, and Bugcrowd.

Published CVEs
1
Software
WP Umbrella
Public credit
CVE-2026-66642

How research becomes a useful public record

The goal is not disclosure for its own sake. The work should improve researcher judgment, give maintainers actionable evidence, and leave defenders with a trustworthy record of what changed.

  1. 01

    Authorize

    Work only in systems you own or control, isolated lab copies of open-source software, or programs that expressly permit testing.

  2. 02

    Validate

    Reproduce the issue, understand the root cause, and minimize collection or disruption.

  3. 03

    Report privately

    Send maintainers or their designated coordinator evidence they can use to act.

  4. 04

    Coordinate a fix

    Answer questions, verify the remediation path, and respect the applicable disclosure rules.

  5. 05

    Publish

    Create a defensive public record with attribution, affected versions, and update guidance.

Maintainer-first disclosure

Verified findings go through the affected project or its designated disclosure program before public publication.

Reproducible evidence

Reports should explain the affected behavior and root cause clearly enough for a maintainer to reproduce and remediate it.

Defensive public learning

Published records focus on who is affected, how to update, what defenders can learn, and who deserves research credit.

Scope and attribution boundary

GreenHat researchers work only in environments they own or control, isolated labs, or programs that expressly authorize testing. We follow applicable scope and rules, minimize collection and disruption, and stop if testing could affect other users or production availability.

This page does not authorize testing of GreenHat, GreenHat clients, or third-party systems, and it is not a public bug-bounty offer. Products, CVE authorities, and research platforms are named for source verification and attribution; inclusion does not imply sponsorship, partnership, or endorsement.

Put the discipline to work

Turn real research habits into stronger security testing

Talk with GreenHat about applying reproducible testing, clear evidence, and remediation-focused reporting to your environment—or use the program guide to build the operating process around the findings you already have.