CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

XLSXviewer (Arbitrary File Deletion)
16 Jan
PROTECTED
WP Load Gallery (Arbitrary File Upload)
16 Jan
PROTECTED
DD Roles (Privilege Escalation)
16 Jan
PROTECTED
Image Gallery Box by CRUDLab (Local File Inclusion)
16 Jan
PROTECTED
User Management (Privilege Escalation) < 1.2
14 Jan
PROTECTED
WR Price List Manager For Woocommerce (Arbitrary File Upload)
13 Jan
PROTECTED
Background Control <= 1.0.5 - Cross-Site Request Forgery to Arbitrary File Deletion
13 Jan
PROTECTED
WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change < 1.6.6
9 Jan
PROTECTED
Multiple Shipping And Billing Address For Woocommerce (Unauthenticated SQL Injection) < 1.3
3 Jan
PROTECTED
Private Messages for UserPro (Unauthenticated Local File Inclusion)
3 Jan
PROTECTED
ARPrice (Unauthenticated SQL Injection)
3 Jan
PROTECTED
ARPrice (PHP Object Injection)
3 Jan
PROTECTED
AutomatorWP (Reflected Cross-Site Scripting) < 5.1.0
18 Dec 2024
PROTECTED
Super Backup & Clone (Arbitrary File Upload) < 2.4
12 Dec 2024
PROTECTED
Print Science Designer (PHP Object Injection) < 1.3.153
11 Dec 2024
PROTECTED
Ninja Forms (Cross-Site Scripting) < 3.8.20
11 Dec 2024
PROTECTED
Grid Plus (Arbitrary Shortcode Execution)
11 Dec 2024
PROTECTED
Opt-In Downloads (Arbitrary File Upload)
11 Dec 2024
PROTECTED
de:branding (Arbitrary Options Update)
11 Dec 2024
PROTECTED
HQ Rental Software (Cross-Site Request Forgery to Arbitrary Options Update)
11 Dec 2024
PROTECTED