CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Doccure (Unauthenticated Arbitrary File Upload) < 1.4.9
8 Sep 2025
PROTECTED
Doccure (Arbitrary User Password Change)
8 Sep 2025
PROTECTED
AutomatorWP - Automator plugin for no-code automations, webhooks & custom integrations in WordPress (Remote Code Execution) < 5.3.7
8 Sep 2025
PROTECTED
Goza - Nonprofit Charity WordPress Theme (Unauthenticated Arbitrary File Upload) < 3.2.3
8 Sep 2025
PROTECTED
AdForest (Authentication Bypass to Admin) < 6.0.10
5 Sep 2025
PROTECTED
Multi Step Form (Arbitrary File Upload) < 1.7.26
5 Sep 2025
PROTECTED
Cloud SAML SSO (Missing Authorization to Unauthenticated Settings Modification) < 1.0.20
5 Sep 2025
PROTECTED
Cloud SAML SSO (Missing Authorization to update option) < 1.0.20
5 Sep 2025
PROTECTED
Rehub (Unauthenticated Arbitrary Shortcode Execution) < 19.9.8
5 Sep 2025
PROTECTED
WordPress Helpdesk Integration (Unauthenticated Local File Inclusion)
4 Sep 2025
PROTECTED
atec Debug (Arbitrary File Deletion) < 1.2.23
3 Sep 2025
PROTECTED
atec Debug (Remote Code Execution) < 1.2.23
3 Sep 2025
PROTECTED
Easy Timer (Remote Code Execution via Shortcode) < 4.2.2
3 Sep 2025
PROTECTED
Make Connector (Arbitrary File Upload)
3 Sep 2025
PROTECTED
Post SMTP (Missing Authorization to Limited Plugin Option Update) < 3.4.2
2 Sep 2025
PROTECTED
Related Posts Lite (Cross-Site Request Forgery)
29 Aug 2025
PROTECTED
iATS Online Forms (SQL Injection via order Parameter) < 1.3
28 Aug 2025
PROTECTED
Slider Revolution (Arbitrary File Read) < 6.7.37
28 Aug 2025
PROTECTED
Video Share VOD - Turnkey Video Site Builder Script (Cross-Site Request Forgery to Command Injection) < 2.7.7
27 Aug 2025
PROTECTED
Xagio SEO (Sensitive Information Exposure via Unprotected Back-Up Files) < 7.1.0.6
27 Aug 2025
PROTECTED