CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Professional Contact Form (Cross-Site Request Forgery to Test Email Sending)
26 Sep 2025
PROTECTED
WP Statistics (Unauthenticated Stored Cross-Site Scripting) < 14.15.5
26 Sep 2025
PROTECTED
cForms - Light speed fast Form Builder (Cross-Site Request Forgery)
26 Sep 2025
PROTECTED
WP-DownloadManager (Arbitrary File Upload) < 1.69
25 Sep 2025
PROTECTED
Featured Image from URL (FIFU) (Unauthenticated Information Exposure via Log File) < 5.2.8
25 Sep 2025
PROTECTED
Featured Image from URL (FIFU) (SQL Injection) < 5.2.8
25 Sep 2025
PROTECTED
System Dashboard (Cross-Site Request Forgery) < 2.8.21
25 Sep 2025
PROTECTED
MultiLoca - WooCommerce Multi Locations Inventory Management (Arbitrary Options Update) < 4.2.9
23 Sep 2025
PROTECTED
WPCasa (Unauthenticated Code Injection) < 1.4.2
22 Sep 2025
PROTECTED
Product Options and Price Calculation Formulas for WooCommerce - Uni CPO (Premium) (Arbitrary File Upload) < 4.9.55
22 Sep 2025
PROTECTED
Miniorange OTP Verification with Firebase (Unauthenticated Privilege Escalation)
19 Sep 2025
PROTECTED
ClickWhale (SQL injection) < 2.5.1
19 Sep 2025
PROTECTED
Custom Login And Signup Widget (Cross-Site Request Forgery)
19 Sep 2025
PROTECTED
Secure Passkeys (Missing Authorization to Passkey Exposure and Deletion) < 1.2.2
19 Sep 2025
PROTECTED
Robcore Netatmo (SQL Injection via Shortcode) < 1.8
19 Sep 2025
PROTECTED
Internal Links Manager (Cross-Site Request Forgery) < 3.0.2
19 Sep 2025
PROTECTED
SureForms - Drag and Drop Form Builder for WordPress (Missing Authorization to Form Creation) < 1.12.1
19 Sep 2025
PROTECTED
Service Finder SMS System (Authentication Bypass)
18 Sep 2025
PROTECTED
Service Finder Bookings (Unauthenticated Privilege Escalation)
18 Sep 2025
PROTECTED
Embed PDF for WPForms (Arbitrary File Upload) < 1.1.6
18 Sep 2025
PROTECTED