CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Avada Builder (Arbitrary Shortcode Execution) < 3.11.14
12 Feb
PROTECTED
JS Help Desk The Ultimate Help Desk & Support Plugin (Unprotected Directory) < 2.8.9
12 Feb
PROTECTED
Avada Theme (Unauthenticated Arbitrary Shortcode Execution) < 7.11.14
12 Feb
PROTECTED
Campress <= 1.35 - Unauthenticated Local File Inclusion
12 Feb
PROTECTED
WP Directorybox Manager (Authentication Bypass)
12 Feb
PROTECTED
Avada Theme (Arbitrary Shortcode Execution) < 7.11.14
12 Feb
PROTECTED
JS Help Desk (Unprotected Directory Access) < 2.8.9
12 Feb
PROTECTED
Avada Builder (Arbitrary Shortcode Execution) < 3.11.14
12 Feb
PROTECTED
Majestic Support - The Leading-Edge Help Desk & Customer Support Plugin (Unprotected Directory) < 1.0.6
11 Feb
PROTECTED
Brizy - Page Builder (Arbitrary File Upload via storeUploads) < 2.6.5
11 Feb
PROTECTED
Security & Malware scan by CleanTalk (Unauthenticated Arbitrary File Upload) < 2.150
11 Feb
PROTECTED
WP Job Board Pro (Unauthenticated Privilege Escalation)
11 Feb
PROTECTED
Real Estate 7 WordPress (Unauthenticated Privilege Escalation) < 3.5.2
11 Feb
PROTECTED
Welcart e-Commerce (Unauthenticated Stored Cross-Site Scripting) < 2.11.10
11 Feb
PROTECTED
Small Package Quotes Purolator Edition (SQL Injection)
11 Feb
PROTECTED
LTL Freight Quotes Unishippers Edition (SQL Injection) < 2.5.9
11 Feb
PROTECTED
WP Abstracts (Cross Site Request Forgery Arbitrary Account Deletion) < 2.7.4
11 Feb
PROTECTED
ShipEngine Shipping Quotes (SQL Injection)
11 Feb
PROTECTED
Ebook Downloader (Unauthenticated SQL Injection)
11 Feb
PROTECTED
All-Images.ai IA Image Bank and Custom Image creation (Arbitrary File Upload) < 1.0.5
11 Feb
PROTECTED