CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

WP Image Uploader (Arbitrary File Deletion)
29 Jan
PROTECTED
WP Image Uploader (Cross-Site Request Forgery )
29 Jan
PROTECTED
Flexible Wishlist for WooCommerce (Stored Cross-Site Scripting) < 1.2.26
28 Jan
PROTECTED
Wise Forms (Stored Cross-Site Scripting)
27 Jan
PROTECTED
Oshine Modules (Server-Side Request Forgery) < 3.3.8
27 Jan
PROTECTED
Akismet Testing
25 Jan
PROTECTED
Akismet
25 Jan
PROTECTED
Custom Product Tabs Lite for WooCommerce ( PHP Object Injection ) < 1.9.1
24 Jan
PROTECTED
ThemeREX Addons (Local File Inclusion via Shortcode) < 2.34.0
24 Jan
PROTECTED
WPBookit (Unauthenticated Arbitrary File Upload) < 1.6.10
24 Jan
PROTECTED
Import WP - Export and Import CSV and XML files to WordPress (Information Exposure Through Unprotected Directory) < 2.14.6
24 Jan
PROTECTED
Atarim (Unauthenticated Stored Cross-Site Scripting) < 4.0.9
24 Jan
PROTECTED
Tourfic (Authenticated (Admin+) Arbitrary File Upload) < 2.15.4
24 Jan
PROTECTED
Post Grid, Slider & Carousel Ultimate (Local File Inclusion) < 1.7
23 Jan
PROTECTED
Post Grid, Slider & Carousel Ultimate (Local File Inclusion) < 1.7
23 Jan
PROTECTED
BMLT Meeting Map (Local File Inclusion) < 2.6.1
22 Jan
PROTECTED
WPBot Pro WordPress Chatbot (Arbitrary File Upload) < 13.5.6
21 Jan
PROTECTED
AI Power: Complete AI Pack (PHP Object Injection) < 1.8.97
21 Jan
PROTECTED
GamiPress (Unauthenticated SQL Injection) < 7.2.2
21 Jan
PROTECTED
GamiPress (Unauthenticated Arbitrary Shortcode Execution) < 7.2.2
21 Jan
PROTECTED