CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

StoryChief (Unauthenticated Arbitrary File Upload) < 1.0.45
15 Aug 2025
PROTECTED
WPGYM - WordPress Gym Management System (Admin Account Creation)
15 Aug 2025
PROTECTED
WPGYM - WordPress Gym Management System (Privilege Escalation)
15 Aug 2025
PROTECTED
School Management System (Arbitrary File Upload)
15 Aug 2025
PROTECTED
School Management System for WordPress (Unauthenticated SQL Injection)
15 Aug 2025
PROTECTED
Al Pack (Missing Authorization to Unauthenticated Premium Feature Activation)
15 Aug 2025
PROTECTED
WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 - Authentication Bypass < 1.8.48
14 Aug 2025
PROTECTED
Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload < 2.20.4
14 Aug 2025
PROTECTED
BizCalendar Web (Local File Inclusion)
14 Aug 2025
PROTECTED
Assistant for NextGEN Gallery (Arbitrary Directory Deletion)
14 Aug 2025
PROTECTED
Icons Factory (Arbitrary File Deletion)
14 Aug 2025
PROTECTED
Tutor LMS Pro - eLearning and online course solution (SQL Injection) < 3.7.1
12 Aug 2025
PROTECTED
WooCommerce Purchase Orders (Arbitrary File Deletion)
11 Aug 2025
PROTECTED
B Blocks (Privilege Escalation) < 2.0.7
11 Aug 2025
PROTECTED
UiCore Elements (Arbitrary File Read) < 1.3.1
11 Aug 2025
PROTECTED
B Slider- Gutenberg Slider Block for WP (Missing Authorization) < 2.0.0
11 Aug 2025
PROTECTED
Eventin (Privilege Escalation) < 4.0.35
8 Aug 2025
PROTECTED
MapSVG (Unauthenticated SQL Injection) < 8.7.4
8 Aug 2025
PROTECTED
CleverReach WP (Unauthenticated SQL Injection)
5 Aug 2025
PROTECTED
Zakra (Missing Authorization Demo Import) < 4.1.6
5 Aug 2025
PROTECTED