CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Traveler Code (SQL Injection)
31 Jan
PROTECTED
Jupiter X Core (SVG Upload to Local File Inclusion) < 4.8.8
31 Jan
PROTECTED
WooCommerce Customers Manager (Privilege Escalation) < 31.4
31 Jan
PROTECTED
WP BASE Booking (Stored Cross-Site Scripting) < 5.1.0
31 Jan
PROTECTED
Traveler Layout Essential For Elementor (Server-Side Request Forgery)
31 Jan
PROTECTED
WooCommerce Product Table Lite (Arbitrary Shortcode Execution & Reflected Cross-Site Scripting) < 3.9.5
30 Jan
PROTECTED
Link Fixer (Unauthenticated Stored Cross-Site Scripting)
30 Jan
PROTECTED
Live2DWebCanvas (Arbitrary File Deletion)
30 Jan
PROTECTED
Borderless - Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg (Remote Code Execution)
30 Jan
PROTECTED
Royal Core (Arbitrary Options Update)
30 Jan
PROTECTED
Media Manager for UserPro (Arbitrary Options Update)
30 Jan
PROTECTED
Media Manager for UserPro (Arbitrary Options Update)
30 Jan
PROTECTED
Single-user-chat (Limited Options Update)
30 Jan
PROTECTED
Music Sheet Viewer (Unauthenticated Arbitrary File Read)
30 Jan
PROTECTED
MWB HubSpot for WooCommerce (Arbitrary Options Update) < 1.6.0
30 Jan
PROTECTED
iControlWP - Multiple WordPress Site Manager (PHP Object Injection) < 4.5.0
30 Jan
PROTECTED
Safe Ai Malware Protection for WP ( Missing Authorization to Unauthenticated Database Export)
30 Jan
PROTECTED
MultiVendorX -The Ultimate WooCommerce Multivendor Marketplace Solution (Unauthenticated Limited Local File Inclusion) < 4.2.15
30 Jan
PROTECTED
Contact Form & SMTP Plugin for WordPress by PirateForms (Arbitrary Shortcode Execution) < 2.6.1
29 Jan
PROTECTED
WooCommerce Wishlist (Unauthenticated Wishlist Disclosure via download_pdf_file Function) < 1.8.8
29 Jan
PROTECTED