CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Reset (Cross-Site Request Forgery to Database Reset)
17 Feb
PROTECTED
Option Editor (Cross-Site Request Forgery to Arbitrary Options Update)
17 Feb
PROTECTED
File Uploads Addon for WooCommerce (Unprotected Directory)
17 Feb
PROTECTED
GetBookingsWp Appointments & Bookings Plugin Basic Version (Privilege Escalation)
17 Feb
PROTECTED
Keap Official Opt-in Forms (Unauthenticated Limited Local File Inclusion)
17 Feb
PROTECTED
s2Member Pro (Unauthenticated PHP Object Injection) < 250214
14 Feb
PROTECTED
Oliver POS - A WooCommerce Point of Sale (Sensitive Information Exposure to Privilege Escalation) < 2.4.2.4
14 Feb
PROTECTED
LTL Freight Quotes - Estes Edition (Unauthenticated SQL Injection) < 3.3.8
14 Feb
PROTECTED
Campress (Unauthenticated Local File Inclusion)
12 Feb
PROTECTED
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL (Unauthenticated PHP Object Injection)
12 Feb
PROTECTED
Avada Builder (Arbitrary Shortcode Execution) < 3.11.14
12 Feb
PROTECTED
JS Help Desk The Ultimate Help Desk & Support Plugin (Unprotected Directory) < 2.8.9
12 Feb
PROTECTED
Avada Theme (Unauthenticated Arbitrary Shortcode Execution) < 7.11.14
12 Feb
PROTECTED
Campress <= 1.35 - Unauthenticated Local File Inclusion
12 Feb
PROTECTED
WP Directorybox Manager (Authentication Bypass)
12 Feb
PROTECTED
Avada Theme (Arbitrary Shortcode Execution) < 7.11.14
12 Feb
PROTECTED
JS Help Desk (Unprotected Directory Access) < 2.8.9
12 Feb
PROTECTED
Avada Builder (Arbitrary Shortcode Execution) < 3.11.14
12 Feb
PROTECTED
Majestic Support - The Leading-Edge Help Desk & Customer Support Plugin (Unprotected Directory) < 1.0.6
11 Feb
PROTECTED
Brizy - Page Builder (Arbitrary File Upload via storeUploads) < 2.6.5
11 Feb
PROTECTED