Shikhali Jamalzade
alisalive · Baku, Azerbaijan
I break things for a living — web apps, Active Directory, cloud, WordPress plugins. If it ships an auth check, I want to know whether it actually holds. Usually it doesn't.
- 7 Certifications
- 5 Tools Built
- 5 CVEs Published
- 20+ Active CVE Submissions
About
16, tenth grade, based in Baku. I started in 2025 with a laptop and too much curiosity — building tools before I could spell "certification," then going back and collecting the certs anyway. No bootcamp, no CS degree yet, just a long list of things I wanted to take apart.
langs: Azerbaijani, Turkish, English
handle: alisalive
Vulnerability Research
A repeatable pipeline for finding 0-days in WordPress plugins: pull candidates from the WordPress.org API, read the code until something smells wrong, prove it in a throwaway Docker box, and report it through WPScan. Rinse, repeat.
Officially confirmed findings
- CVE-2026-14923 — Sync Post With Other Site plugin — CWE-863 Missing Authorization
- CVE-2026-15939 — Simple Restrict plugin — CWE-863, Contributor+ restricted-content REST disclosure
- CVE-2026-16547 — WP REST API Log plugin — Missing Authorization
- CVE-2026-16546 — Wired Impact Volunteer Management plugin — Missing Authorization
- CVE-2026-17515 — MLS Import plugin — Missing Authorization / missing nonce & capability check
15+ more reports currently sitting in responsible-disclosure limbo with plugin vendors via WPScan.
Technical details for pending findings stay under wraps until the vendor ships a patch — that's the deal with responsible disclosure.
Recognition
RedSEC got a nod from Risto Vaarandi (TalTech professor, creator of the SEC framework) and Clayton Dukes (CEO, LogZilla).
Experience
- WordPress Plugin CVE Research (Independent) (2026–Present)
20+ WordPress vulnerability findings submitted for responsible disclosure - Authorized Penetration Tests (2025)
2 authorized penetration tests for real client environments - Bug Bounty & Vulnerability Research (2025–Present)
Active vulnerability research and bug bounty hunting across Intigriti and HackerOne programs - CTF Competitions (2025–Present)
15+ TryHackMe rooms completed, 5+ VulnHub machines solved, 2+ HackTheBox machines completed - Open Source Tools & Technical Writing (2025–Present)
Medium / Infosec Write-ups
Contact
Found a hole in something, or just want to talk shop? Reach out.
- email: camalzadss@gmail.com
- github: github.com/alisalive
- linkedin: linkedin.com/in/camalzads