CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Javo Core (Unauthenticated Privilege Escalation in ajax_signup) < 3.0.0.266
7 Mar
PROTECTED
Javo Core (Unauthenticated Privilege Escalation in ajax_signup) < 3.0.0.266
7 Mar
PROTECTED
Golo - Directory & Listing, Travel WordPress Theme (Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change) < 1.6.11
6 Mar
PROTECTED
InWave Jobs (Unauthenticated Privilege Escalation via Password Reset)
6 Mar
PROTECTED
InWave Jobs (Unauthenticated Privilege Escalation via Password Reset)
6 Mar
PROTECTED
Golo - Directory & Listing, Travel WordPress Theme (Missing Authorization to Privilege Escalation) < 1.6.11
6 Mar
PROTECTED
WP Real Estate Manager <= 2.8 - Authentication Bypass via Account Takeover
4 Mar
PROTECTED
Homey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_register
4 Mar
PROTECTED
Homey (Unauthenticated Privilege Escalation)
4 Mar
PROTECTED
Newscrunch (Arbitrary File Upload) < 1.8.4.1
3 Mar
PROTECTED
SetSail Membership (Authentication Bypass) < 1.1
28 Feb
PROTECTED
Academist Membership (Authentication Bypass) < 1.2
28 Feb
PROTECTED
Alloggio Membership (Authentication Bypass) < 1.2
28 Feb
PROTECTED
Nokri - Job Board WordPress Theme (Unauthenticated Arbitrary Password Change) < 1.6.3
28 Feb
PROTECTED
DHVC Form (Unauthenticated Privilege Escalation) < 2.4.8
27 Feb
PROTECTED
Test rule -create < 1.5.0
26 Feb
PROTECTED
Private Content (Unauthenticated Privilege Escalation)
24 Feb
PROTECTED
Fresh Framework (Unauthenticated Remote Code Execution)
24 Feb
PROTECTED
WC Place Order Without Payment (Unauthenticated Local File Inclusion) < 2.6.8
23 Feb
PROTECTED
Pearl - Corporate Business (Unauthenticated Local File Inclusion) < 3.4.8
23 Feb
PROTECTED