Security engineer and SDET based in Dhaka, Bangladesh. I work at the
intersection of application security and test automation — finding
vulnerabilities before attackers do, and building frameworks to keep
software reliable at scale.
I'm currently Lead Application Security Engineer at WPDeveloper, where I lead a security team protecting 6+ million users across
products like Essential Addons, Easy.jobs, xCloud, and Templately. My security research has resulted in
250+ CVE assignments.
I contribute to WordPress as a Core & Test Contributor, and I enjoy building test automation tooling with Playwright.
What I write about
Application security and vulnerability research
Test automation with Playwright, Cypress, and Selenium
Linux, CI/CD, and DevOps workflows
Open source and the WordPress ecosystem
250+CVEs Assigned
181Blog Posts
WordPressCore Contributor
Skills
AppSec Playwright Test Automation WordPress Python CI/CD Linux
CVE-2026-7537 is a CVSS 7.2 High severity Arbitrary File Upload vulnerability in the MDJM Event Management WordPress plugin (<= 1.7.8.3) that lets an authenticated administrator upload PHP webshells and execute remote code.
CVE-2026-7654 is a CVSS 8.8 PHP Object Injection flaw in Admin Columns that lets a Contributor trigger RCE by injecting a serialized object into a custom post meta field.
CVE-2026-8438 is a CVSS 7.2 unauthenticated stored XSS in All-In-One Security (AIOS) for WordPress. Attackers can inject scripts that run in an admin's browser.
Set up Mailpit on macOS to intercept all outgoing emails from your local WordPress, Laravel, and custom PHP sites — no real emails sent, everything visible in a browser UI.
Real SQA job circulars from WPDeveloper — review actual requirements for Junior Test Engineer and xCloud SQA roles to sharpen your skills and CV for the market.