CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Accounting for WooCommerce (Unauthenticated Local File Inclusion) < 1.6.9
27 Mar 2025
PROTECTED
Essential Real Estate (Unauthenticated Local File Inclusion) < 5.2.1
27 Mar 2025
PROTECTED
WP Travel Engine (Unauthenticated Local File Inclusion) < 6.3.6
27 Mar 2025
PROTECTED
postMash Custom - custom post order (Unauthenticated SQL Injection)
26 Mar 2025
PROTECTED
User Registration & Membership (Privilege Escalation) < 4.1.2
24 Mar 2025
PROTECTED
Docpro (Unauthenticated Local File Inclusion)
23 Mar 2025
PROTECTED
Instant Appointment (Unauthenticated Arbitrary File Upload)
20 Mar 2025
PROTECTED
Age Gate (Unauthenticated Local File Inclusion) < 3.5.4
19 Mar 2025
PROTECTED
CozyStay (Arbitrary Action Execution) < 1.7.1
18 Mar 2025
PROTECTED
Improve My City (Stored Cross-Site Scripting)
18 Mar 2025
PROTECTED
FoodBakery Delivery Restaurant Directory WordPress Theme (Missing Authorization) < 4.8
18 Mar 2025
PROTECTED
BoomBox Theme Extensions (Privilege Escalation) < 1.8.1
18 Mar 2025
PROTECTED
s2Member Pro (Local File Inclusion)
18 Mar 2025
PROTECTED
MinimogWP - Theme (Unauthenticated Local PHP File Inclusion) < 3.8.0
18 Mar 2025
PROTECTED
Altair (Unauthenticated Arbitrary Options Update) < 5.2.5
18 Mar 2025
PROTECTED
Service Finder Bookings (Unauthenticated Privilege Escalation via Account Takeover) < 5.1
18 Mar 2025
PROTECTED
CozyStay (Unauthenticated PHP Object Injection) < 1.7.1
18 Mar 2025
PROTECTED
GetShop ecommerce (Unauthenticated Local File Inclusion)
17 Mar 2025
PROTECTED
LinkedIn Lite (Unauthenticated Local File Inclusion)
17 Mar 2025
PROTECTED
Custom Field List Widget (Unauthenticated Local File Inclusion)
17 Mar 2025
PROTECTED