CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites - PostX (Unauthenticated Sensitive Information Exposure) < 5.0.4
20 Dec 2025
PROTECTED
Redirection for Contact Form 7 (Arbitrary File Copy) < 3.2.8
20 Dec 2025
PROTECTED
SureForms (Unauthenticated Stored Cross-Site Scripting) < 2.2.1
20 Dec 2025
PROTECTED
File Uploader for WooCommerce (Arbitrary File Upload via add-image-data) < 1.0.4
19 Dec 2025
PROTECTED
Flex Store Users (Unauthenticated Privilege Escalation) < 1.1.1
19 Dec 2025
PROTECTED
HTML5 Audio Player - The Ultimate No-Code Podcast, MP3 & Audio Player (Unauthenticated Server-Side Request Forgery) < 2.5.2
18 Dec 2025
PROTECTED
Photo Gallery, Sliders, Proofing and Themes - NextGEN Gallery (Local File Inclusion) < 4.0.0
17 Dec 2025
PROTECTED
Demo Importer Plus (Privilege Escalation) < 2.0.9
17 Dec 2025
PROTECTED
Hummingbird (Unauthenticated Sensitive Information Exposure via Log File) < 3.18.1
17 Dec 2025
PROTECTED
Ninja Forms - The Contact Form Builder That Grows With You (Unauthenticated Sensitive Information Exposure) < 3.13.3
16 Dec 2025
PROTECTED
WPCOM Member (Authentication Bypass via Weak OTP) < 1.7.17
15 Dec 2025
PROTECTED
Fox LMS - WordPress LMS Plugin (Unauthenticated Privilege Escalation) < 1.0.5.2
15 Dec 2025
PROTECTED
Booking Calendar (Unauthenticated SQL Injection via dates_to_check) < 10.14.9
15 Dec 2025
PROTECTED
WP Directory Kit (Unauthenticated SQL Injection) < 1.4.8
12 Dec 2025
PROTECTED
Export WP Page to Static HTML & PDF (Unauthenticated Cookie Exposure via Log File) < 5.0.0
12 Dec 2025
PROTECTED
Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter
12 Dec 2025
PROTECTED
WP3D Model Import Viewer <= 1.0.7 - Authenticated (Contributor+) Arbitrary File Upload
12 Dec 2025
PROTECTED
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
12 Dec 2025
PROTECTED
LT Unleashed (Local File Inclusion via 'template' Parameter)
11 Dec 2025
PROTECTED
Visitor Logic Lite (PHP Object Injection via Cookie) < 1.0.4
11 Dec 2025
PROTECTED