CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Community Events (Unauthenticated SQL Injection) < 1.5.2
7 Oct 2025
PROTECTED
Motors - Car Dealership & Classified Listings Plugin (Arbitrary File Deletion) < 1.4.90
7 Oct 2025
PROTECTED
RegistrationMagic - Custom Registration Forms, User Registration, Payment, and User Login (SQL Injection) < 6.0.6.3
7 Oct 2025
PROTECTED
Progress Planner (Missing Authorization to Arbitrary Options Update) < 1.8.1
6 Oct 2025
PROTECTED
Cost Calculator Builder (Missing Authorization) < 3.5.33
3 Oct 2025
PROTECTED
OAuth Single Sign On - SSO [OAuth Client] (Authentication Bypass) < 6.26.13
3 Oct 2025
PROTECTED
Spirit Framework (Privilege Escalation) < 1.2.15
2 Oct 2025
PROTECTED
AP Background (Arbitrary File Upload) < 3.8.3
2 Oct 2025
PROTECTED
TextBuilder (Cross-Site Request Forgery to Privilege Escalation) < 1.2.0
2 Oct 2025
PROTECTED
RestroPress - Online Food Ordering System (Unauthenticated Information Exposure to Authentication Bypass) < 3.1.9.2
2 Oct 2025
PROTECTED
JoomSport (Local File Inclusion) < 5.7.4
2 Oct 2025
PROTECTED
WP Dispatcher (SQL Injection via Shortcode)
2 Oct 2025
PROTECTED
Appy Pie Connect for WooCommerce (Missing Authorization to Unauthenticated Privilege Escalation) < 1.1.3
2 Oct 2025
PROTECTED
WPRecovery (Unauthenticated SQL Injection)
2 Oct 2025
PROTECTED
Copypress Rest API (Unauthenticated Remote Code Execution) < 1.2.1
29 Sep 2025
PROTECTED
Tiny Bootstrap Elements Light (Unauthenticated Local File Inclusion)
29 Sep 2025
PROTECTED
Bei Fen - WordPress Backup Plugin (Local File Inclusion)
29 Sep 2025
PROTECTED
AffiliateWP (Unauthenticated SQL Injection) < 2.29.0
29 Sep 2025
PROTECTED
HidePost (Cross-Site Request Forgery)
26 Sep 2025
PROTECTED
Sync Feedly (Cross-Site Request Forgery to Sync Trigger)
26 Sep 2025
PROTECTED