CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Import WP - Export and Import CSV and XML files to WordPress (Information Exposure Through Unprotected Directory) < 2.14.6
24 Jan
PROTECTED
Atarim (Unauthenticated Stored Cross-Site Scripting) < 4.0.9
24 Jan
PROTECTED
Tourfic (Authenticated (Admin+) Arbitrary File Upload) < 2.15.4
24 Jan
PROTECTED
Post Grid, Slider & Carousel Ultimate (Local File Inclusion) < 1.7
23 Jan
PROTECTED
Post Grid, Slider & Carousel Ultimate (Local File Inclusion) < 1.7
23 Jan
PROTECTED
BMLT Meeting Map (Local File Inclusion) < 2.6.1
22 Jan
PROTECTED
WPBot Pro WordPress Chatbot (Arbitrary File Upload) < 13.5.6
21 Jan
PROTECTED
AI Power: Complete AI Pack (PHP Object Injection) < 1.8.97
21 Jan
PROTECTED
GamiPress (Unauthenticated SQL Injection) < 7.2.2
21 Jan
PROTECTED
GamiPress (Unauthenticated Arbitrary Shortcode Execution) < 7.2.2
21 Jan
PROTECTED
GamiPress (Unauthenticated Arbitrary Shortcode Execution) < 7.2.2
21 Jan
PROTECTED
AdForest (Authentication Bypass) < 5.1.9
21 Jan
PROTECTED
Easy Real Estate (Privilege Escalation)
20 Jan
PROTECTED
RealHomes (Privilege Escalation)
20 Jan
PROTECTED
Small Package Quotes - Unishippers Edition (Unauthenticated SQL Injection) < 2.4.9
18 Jan
PROTECTED
LTL Freight Quotes Worldwide Express Edition (SQL Injection) < 5.0.21
18 Jan
PROTECTED
Adifier System (Unauthenticated Arbitrary Password Reset) < 3.1.8
17 Jan
PROTECTED
GravityForms (Stored Cross-Site Scripting) < 2.9.2
16 Jan
PROTECTED
Multi Uploader for Gravity Forms (Unauthenticated Arbitrary File Upload)
16 Jan
PROTECTED
Quick Count (Unauthenticated PHP Object Injection)
16 Jan
PROTECTED