CROWD-SOURCED
VULNERABILITIES DATABASE
Kalrav AI Agent (Unauthenticated Arbitrary File Upload)
23 Jan
PROTECTED
Frontis Blocks (Unauthenticated Server-Side Request Forgery) < 1.1.7
23 Jan
PROTECTED
Administrative Shortcodes (Local File Inclusion via Shortcode Attribute) < 0.3.5
23 Jan
PROTECTED
User Submitted Posts - Enable Users to Submit Posts from the Front End (Unauthenticated Stored Cross-Site Scripting via Custom Field) < 20260110
23 Jan
PROTECTED
Melapress Role Editor (Privilege Escalation via Secondary Role Assignment) < 1.2.0
22 Jan
PROTECTED
LA-Studio Element Kit for Elementor (Unauthenticated Privilege Escalation to Administrative User Creation via lakit_bkrole parameter) < 1.6.0
21 Jan
PROTECTED
Creator LMS - The LMS for Creators, Coaches, and Trainers (Arbitrary Options Update) < 1.1.13
20 Jan
PROTECTED
NotificationX (Cross-Site Scripting via 'nx-preview') < 3.2.1
20 Jan
PROTECTED
Nexter Extension - Site Enhancements Toolkit (Unauthenticated PHP Object Injection) < 4.4.7
20 Jan
PROTECTED
Academy LMS - WordPress LMS Plugin for Complete eLearning Solution (Privilege Escalation via Account Takeover) < 3.5.1
20 Jan
PROTECTED
Poll, Survey & Quiz Maker Plugin by Opinion Stage (Cross-Site Scripting) < 19.6.25
19 Jan
PROTECTED
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Build Your Own Amazon, eBay, Etsy (Insecure Direct Object Reference to PayPal Account Takeover) < 4.2.5
19 Jan
PROTECTED
Antideo Email Validator (Unauthenticated SQL Injection)
16 Jan
PROTECTED
Powerlift (Unauthenticated Local File Inclusion) < 3.2.1
16 Jan
PROTECTED
The Aisle (Unauthenticated Local File Inclusion) < 2.9.1
16 Jan
PROTECTED
Demo Importer Plus (Blind XML External Entity Injection via SVG File Upload) < 2.0.10
16 Jan
PROTECTED
Modular DS (Unauthenticated Privilege Escalation) < 2.6.0
16 Jan
PROTECTED
Registration & Login with Mobile Phone Number for WooCommerce (Authentication Bypass) < 1.3.2
16 Jan
PROTECTED
RegistrationMagic (Privilege Escalation via admin_order) < 6.0.7.2
16 Jan
PROTECTED
g-FFL Checkout (Unauthenticated Arbitrary File Upload) < 2.1.1
15 Jan
PROTECTED
Crowdsourced Patches for Crowdsourced Vulnerabilities.
© 2026. All rights reserved.