CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

GamiPress (Unauthenticated Arbitrary Shortcode Execution) < 7.2.2
21 Jan
PROTECTED
AdForest (Authentication Bypass) < 5.1.9
21 Jan
PROTECTED
Easy Real Estate (Privilege Escalation)
20 Jan
PROTECTED
RealHomes (Privilege Escalation)
20 Jan
PROTECTED
Small Package Quotes - Unishippers Edition (Unauthenticated SQL Injection) < 2.4.9
18 Jan
PROTECTED
LTL Freight Quotes Worldwide Express Edition (SQL Injection) < 5.0.21
18 Jan
PROTECTED
Adifier System (Unauthenticated Arbitrary Password Reset) < 3.1.8
17 Jan
PROTECTED
GravityForms (Stored Cross-Site Scripting) < 2.9.2
16 Jan
PROTECTED
Multi Uploader for Gravity Forms (Unauthenticated Arbitrary File Upload)
16 Jan
PROTECTED
Quick Count (Unauthenticated PHP Object Injection)
16 Jan
PROTECTED
Background animation blocks (Unauthenticated Local File Inclusion)
16 Jan
PROTECTED
XLSXviewer (Arbitrary File Deletion)
16 Jan
PROTECTED
WP Load Gallery (Arbitrary File Upload)
16 Jan
PROTECTED
DD Roles (Privilege Escalation)
16 Jan
PROTECTED
Image Gallery Box by CRUDLab (Local File Inclusion)
16 Jan
PROTECTED
User Management (Privilege Escalation) < 1.2
14 Jan
PROTECTED
WR Price List Manager For Woocommerce (Arbitrary File Upload)
13 Jan
PROTECTED
Background Control <= 1.0.5 - Cross-Site Request Forgery to Arbitrary File Deletion
13 Jan
PROTECTED
WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change < 1.6.6
9 Jan
PROTECTED
Multiple Shipping And Billing Address For Woocommerce (Unauthenticated SQL Injection) < 1.3
3 Jan
PROTECTED