CROWD-SOURCED
VULNERABILITIES DATABASE
Cookie Notice & Consent (Unauthenticated Stored Cross-Site Scripting via post_meta) < 1.6.6
8 Oct
PROTECTED
Community Events (Unauthenticated SQL Injection) < 1.5.2
8 Oct
PROTECTED
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers (Unauthenticated SQL Injection) < 2.1.4
8 Oct
PROTECTED
Search & Go - Directory WordPress Theme (Privilege Escalation) < 2.8
8 Oct
PROTECTED
RegistrationMagic - Custom Registration Forms, User Registration, Payment, and User Login (SQL Injection) < 6.0.6.3
7 Oct
PROTECTED
Motors - Car Dealership & Classified Listings Plugin (Arbitrary File Deletion) < 1.4.90
7 Oct
PROTECTED
Community Events (Unauthenticated SQL Injection) < 1.5.2
7 Oct
PROTECTED
Progress Planner (Missing Authorization to Arbitrary Options Update) < 1.8.1
6 Oct
PROTECTED
OAuth Single Sign On - SSO [OAuth Client] (Authentication Bypass) < 6.26.13
3 Oct
PROTECTED
Cost Calculator Builder (Missing Authorization) < 3.5.33
3 Oct
PROTECTED
WP Dispatcher (SQL Injection via Shortcode)
2 Oct
PROTECTED
WPRecovery (Unauthenticated SQL Injection)
2 Oct
PROTECTED
Appy Pie Connect for WooCommerce (Missing Authorization to Unauthenticated Privilege Escalation) < 1.1.3
2 Oct
PROTECTED
JoomSport (Local File Inclusion) < 5.7.4
2 Oct
PROTECTED
RestroPress - Online Food Ordering System (Unauthenticated Information Exposure to Authentication Bypass) < 3.1.9.2
2 Oct
PROTECTED
TextBuilder (Cross-Site Request Forgery to Privilege Escalation) < 1.2.0
2 Oct
PROTECTED
AP Background (Arbitrary File Upload) < 3.8.3
2 Oct
PROTECTED
Spirit Framework (Privilege Escalation) < 1.2.15
2 Oct
PROTECTED
AffiliateWP (Unauthenticated SQL Injection) < 2.29.0
29 Sep
PROTECTED
Bei Fen - WordPress Backup Plugin (Local File Inclusion)
29 Sep
PROTECTED
Crowdsourced Patches for Crowdsourced Vulnerabilities.
© 2025. All rights reserved.