CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

OAuth Single Sign On (Authentication Bypass)
11 Dec 2024
PROTECTED
WP Courses LMS (Arbitrary User Meta Update) < 3.2.22
11 Dec 2024
PROTECTED
Vayu Blocks (Arbitrary Plugin Installation/Activation) < 1.2.0
11 Dec 2024
PROTECTED
Product Carousel Slider(Local File Inclusion) < 1.10.0
11 Dec 2024
PROTECTED
Grid Plus (Arbitrary Shortcode Execution)
11 Dec 2024
PROTECTED
RapidLoad (Missing Authorization to Authenticated) < 2.4.3
10 Dec 2024
PROTECTED
Active Products Tables for WooCommerce (Unauthenticated Arbitrary Shortcode Execution) < 1.0.6.6
9 Dec 2024
PROTECTED
Best WordPress Gallery Plugin (Authenticated Directory Traversal ) < 2.4.27
9 Dec 2024
PROTECTED
WPForms (Missing Authorization to Authenticated) < 1.9.2.2
9 Dec 2024
PROTECTED
Gallery (Authenticated PHP Object Injection)
6 Dec 2024
PROTECTED
Verowa Connect - Unauthenticated SQL Injection < 3.0.2
5 Dec 2024
PROTECTED
SV100 Companion - Arbitrary Options Update
5 Dec 2024
PROTECTED
AI Quiz | Quiz Maker (Arbitrary Options Update)
5 Dec 2024
PROTECTED
WP Hide & Security Enhancer (Arbitrary File Contents Deletion) < 2.5.2
5 Dec 2024
PROTECTED
YouTube Gallery and Vimeo Gallery Plugin (SQL Injection) < 2.4.3
5 Dec 2024
PROTECTED
Swift Performance Lite (Unauthenticated Local PHP File Inclusion) < 2.3.7.2
5 Dec 2024
PROTECTED
KiviCare (SQL Injection) < 3.6.5
5 Dec 2024
PROTECTED
Free Responsive Stars Testimonials (Local File Inclusion) < 3.3.4
4 Dec 2024
PROTECTED
Authors List (Arbitrary Shortcode Execution)
3 Dec 2024
PROTECTED
Funnelforms Free (PHP Object Injection)
3 Dec 2024
PROTECTED