CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Funnel Builder by FunnelKit (Unauthenticated Local File Inclusion) < 3.9.1
23 Feb
PROTECTED
Majestic Support (Unauthenticated Local File Inclusion) < 1.0.7
23 Feb
PROTECTED
Pearl - Corporate Business (Unauthenticated Local File Inclusion) < 3.4.8
23 Feb
PROTECTED
Flexmls IDX (Unauthenticated PHP Object Injection) < 3.14.28
22 Feb
PROTECTED
Helloprint (Unauthenticated Arbitrary File Deletion)
22 Feb
PROTECTED
Migration, Backup, Staging - WPvivid (Arbitrary File Upload) < 0.9.113
21 Feb
PROTECTED
Show Me The Cookies (Unauthenticated Arbitrary Shortcode Execution)
21 Feb
PROTECTED
Mambo Importer (PHP Object Injection)
21 Feb
PROTECTED
Custom Post Type Date Archives (Missing Authorization to Unauthenticated Arbitrary Shortcode Execution)
21 Feb
PROTECTED
LTL Freight Quotes - Purolator Edition (Unauthenticated SQL Injection) < 2.2.4
21 Feb
PROTECTED
IP2Location Country Blocker (Missing Authorization) < 2.38.9
21 Feb
PROTECTED
Saoshyant Slider (Unauthenticated PHP Object Injection)
21 Feb
PROTECTED
Residential Address Detection (Unauthenticated Arbitrary Options Update) < 2.5.5
21 Feb
PROTECTED
SS Quiz <= 2.0.5 - Unauthenticated PHP Object Injection
21 Feb
PROTECTED
WooCommerce Food - Restaurant Menu & Food ordering (Unauthenticated Arbitrary Shortcode Execution) < 3.3.3
19 Feb
PROTECTED
Subscribe2 - Form, Email Subscribers & Newsletters (Unauthenticated Stored Cross-Site Scripting) < 10.44
18 Feb
PROTECTED
Trash Duplicate and 301 Redirect (Arbitrary Post Deletion)
18 Feb
PROTECTED
Team Builder For WPBakery Page Builder(Formerly Visual Composer) (Local File Inclusion)
18 Feb
PROTECTED
Post SMTP( Stored Cross-Site Scripting ) < 3.1.0
17 Feb
PROTECTED
CarSpot Dealership WordPress Classified Theme (Arbitrary Password Reset/Account Takeover) < 2.4.4
17 Feb
PROTECTED