CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Backup and Staging by WP Time Capsule (Arbitrary File Upload) < 1.22.22
15 Nov 2024
PROTECTED
WP Activity Log (Cross-Site Scripting) < 5.2.2
14 Nov 2024
PROTECTED
Tripetto (Unauthentiated Stored Cross Site Scripting )
14 Nov 2024
PROTECTED
Really Simple Security < 9.1.2
14 Nov 2024
PROTECTED
Chartify - WordPress Chart Plugin (Unauthenticated Local File Inclusion) < 2.9.6
13 Nov 2024
PROTECTED
Migration, Backup, Staging - WPvivid (PHP Object Injection) < 0.9.108
13 Nov 2024
PROTECTED
The FOX - Currency Switcher Professional for WooCommerce (Arbitrary Shortcode Execution) < 1.4.2.3
12 Nov 2024
PROTECTED
MultiManager WP (Authentication Bypass) < 1.1.0
12 Nov 2024
PROTECTED
Advanced Order Export For WooCommerce (PHP Object Injection) < 3.5.6
12 Nov 2024
PROTECTED
GPX Viewer (Authenticated Arbitrary File Creation)
12 Nov 2024
PROTECTED
WP Project Manager (Insecure Direct Object Reference to Unauthenticated Authorization Bypass) < 2.6.14
12 Nov 2024
PROTECTED
WP Photo Album Plus (Arbitrary Shortcode Execution) < 8.9.01.001
10 Nov 2024
PROTECTED
Debug Tool (Arbitrary File Creation)
8 Nov 2024
PROTECTED
CE21 Suite (JWT Token Disclosure)
8 Nov 2024
PROTECTED
Th Shop Mania (Arbitrary Plugin Installation/Activation) < 1.5.0
8 Nov 2024
PROTECTED
Top Store (Arbitrary Plugin Installation/Activation) < 1.5.5
8 Nov 2024
PROTECTED
Cowidgets (Post Disclosure)
8 Nov 2024
PROTECTED
Everest Backup - WordPress Cloud Backup, Migration, Restore & Cloning Plugin (Sensitive Invormation Disclosure) < 2.2.14
5 Nov 2024
PROTECTED
Event Post (Cross-Site Scripting) < 5.9.7
5 Nov 2024
PROTECTED
MapPress Maps for WordPress (Cross-Site Scripting) < 2.94.2
5 Nov 2024
PROTECTED