CROWD-SOURCED
VULNERABILITIES DATABASE
SureForms - Drag and Drop Form Builder for WordPress (Missing Authorization to Form Creation) < 1.12.1
19 Sep
PROTECTED
Service Finder SMS System (Authentication Bypass)
18 Sep
PROTECTED
Service Finder Bookings (Unauthenticated Privilege Escalation)
18 Sep
PROTECTED
Embed PDF for WPForms (Arbitrary File Upload) < 1.1.6
18 Sep
PROTECTED
Kubio AI Page Builder (Missing Authorization Plugin Installation) < 2.6.5
18 Sep
PROTECTED
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages (Arbitrary Plugin Installation) < 3.4.4
17 Sep
PROTECTED
StoreEngine - Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More (Arbitrary File Upload) < 1.5.1
16 Sep
PROTECTED
Catch Dark Mode (Local File Inclusion) < 2.0.1
16 Sep
PROTECTED
WP Import - Ultimate CSV XML Importer for WordPress (Arbitrary File Deletion) < 7.28
16 Sep
PROTECTED
WP Import - Ultimate CSV XML Importer for WordPress (Remote Code Execution via Code Injection) < 7.29
16 Sep
PROTECTED
The Hack Repair Guy's Plugin Archiver (Arbitrary File Deletion) < 3.1.1
12 Sep
PROTECTED
LWS Cleaner (Arbitrary File Deletion) < 2.4.2
11 Sep
PROTECTED
The Events Calendar (Unauthenticated SQL Injection) < 6.15.1.1
11 Sep
PROTECTED
Catalog Importer, Scraper & Crawler (Unauthenticated PHP Code Injection)
10 Sep
PROTECTED
All in one Minifier (Unauthenticated SQL Injection) < 3.3
10 Sep
PROTECTED
Ultimate Classified Listings (Local File Inclusion)
10 Sep
PROTECTED
My WP Translate (Arbitrary Options Update)
10 Sep
PROTECTED
Propovoice (Unauthenticated Arbitrary File Read) < 1.7.8
10 Sep
PROTECTED
Time Tracker (Arbitrary Options Update and Limited Data Deletion) < 3.2.0
10 Sep
PROTECTED
Import any XML, CSV or Excel File to WordPress (Unsafe File Upload) < 3.9.4
9 Sep
PROTECTED
Crowdsourced Patches for Crowdsourced Vulnerabilities.
© 2025. All rights reserved.