CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Use-your-Drive | Google Drive plugin for WordPress (Stored Cross-Site Scripting) < 3.3.2
4 Aug
PROTECTED
WP Import Export Lite (Arbitrary File Upload) < 3.9.30
4 Aug
PROTECTED
SEO Metrics (Privilege Escalation)
1 Aug
PROTECTED
Woffice Core (Arbitrary File Deletion) < 5.4.27
1 Aug
PROTECTED
Brave Conversion Engine - PRO (Authentication Bypass) < 0.8.0
1 Aug
PROTECTED
WP CTA - Call To Action Plugin, Sticky CTA, Sticky Buttons (Missing Authorization) < 1.7.1
1 Aug
PROTECTED
WP CTA - Call To Action Plugin, Sticky CTA, Sticky Buttons (Missing Authorization) < 1.7.1
1 Aug
PROTECTED
BerqWP (Arbitrary File Upload) < 2.2.44
31 Jul
PROTECTED
Service Finder Bookings (Authentication Bypass) < 6.1
31 Jul
PROTECTED
Service Finder SMS System (Unauthenticated Privilege Escalation) < 3.0.0
31 Jul
PROTECTED
AI Engine (Arbitrary File Upload) < 2.9.5
30 Jul
PROTECTED
NinjaScanner - Virus & Malware scan (Arbitrary File Deletion) < 3.2.6
30 Jul
PROTECTED
Bricks Builder (SQL Injection) < 2.0
28 Jul
PROTECTED
Bonanza - WooCommerce Free Gifts Lite (Missing Authorization)
28 Jul
PROTECTED
Kallyas (Arbitrary Folder Deletion) < 4.22.0
25 Jul
PROTECTED
MinimogWP - The High Converting eCommerce WordPress Theme (Unauthenticated Price Manipulation) < 3.9.1
25 Jul
PROTECTED
Kallyas (Local File Inclusion) < 4.22.0
25 Jul
PROTECTED
Frontend File Manager (Arbitrary Post Deletion) < 22.0
24 Jul
PROTECTED
Frontend File Manager (Missing Authorization to Unauthenticated Arbitrary Post Deletion) < 22.0
24 Jul
PROTECTED
Droip (Missing Authorization to Many Actions)
24 Jul
PROTECTED