CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Shopper Approved Reviews (Missing Authorization to Authenticated)
1 Apr
PROTECTED
User Registration & Membership (Authentication Bypass) < 4.1.3
1 Apr
PROTECTED
Salon booking system (Authenticated Privilege Escalation)
1 Apr
PROTECTED
HTML Forms (Unauthenticated Stored Cross-Site Scripting) < 1.5.2
1 Apr
PROTECTED
WP Pro Real Estate 7 (Arbitrary File Upload) < 3.5.5
31 Mar
PROTECTED
Import Export Suite for CSV and XML Datafeed (Authenticated Arbitrary File Upload) < 7.19.1
31 Mar
PROTECTED
WP RealEstate (Authentication Bypass) < 1.6.27
31 Mar
PROTECTED
Booster for WooCommerce (Stored Cross-Site Scripting) < 7.2.6
31 Mar
PROTECTED
SMS Alert Order Notifications WooCommerce (Privilege Escalation) < 3.8.0
31 Mar
PROTECTED
Checkout Mestres do WP for WooCommerce (Unauthenticated Arbitrary Options Update) < 8.7.5.1
28 Mar
PROTECTED
Sunshine Photo Cart (Unauthenticated PHP Object Injection) < 3.4.11
28 Mar
PROTECTED
So-Called Air Quotes (Unauthenticated Arbitrary Shortcode Execution)
28 Mar
PROTECTED
Inline Image Upload for BBPress (Authenticated Arbitrary File Upload) < 1.1.20
28 Mar
PROTECTED
SoJ Soundslides (Authenticated Arbitrary File Upload)
28 Mar
PROTECTED
MDJM Event Management (Authenticated PHP Object Injection) < 1.7.5.3
28 Mar
PROTECTED
Pop-Up Chop Chop (Authenticated Local File Inclusion) kuppu
28 Mar
PROTECTED
CM Download Manager (Unauthenticated Arbitrary File Deletion) < 3.0.0
27 Mar
PROTECTED
JS Help Desk (Unauthenticated Arbitrary File Deletion) < 2.9.3
27 Mar
PROTECTED
Rapyd Payment Extension for WooCommerce (Unauthenticated PHP Object Injection)
27 Mar
PROTECTED
Accounting for WooCommerce (Unauthenticated Local File Inclusion) < 1.6.9
27 Mar
PROTECTED