CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

RapidResult (SQL Injection)
23 Oct 2025
PROTECTED
Email Tracker <= 5.3.12 - Authenticated (Admin+) SQL Injection
21 Oct 2025
PROTECTED
Event Tickets and Registration (Unauthenticated Ticket Payment Bypass) < 5.26.6
17 Oct 2025
PROTECTED
PPOM - Product Addons & Custom Fields for WooCommerce (Unauthenticated Arbitrary File Upload) < 33.0.16
17 Oct 2025
PROTECTED
PPOM - Product Addons & Custom Fields for WooCommerce (Unauthenticated SQL Injection) < 33.0.16
17 Oct 2025
PROTECTED
Theme Editor (Remote Code Execution) < 3.1
17 Oct 2025
PROTECTED
Classified Pro <= 1.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
15 Oct 2025
PROTECTED
Truelysell Core (Unauthenticated Arbitrary User Password Change via Shortcode)
15 Oct 2025
PROTECTED
Felan Framework (Hardcoded Credentials) < 1.1.5
15 Oct 2025
PROTECTED
XStore | Multipurpose WooCommerce Theme (Local File Inclusion) < 9.6
14 Oct 2025
PROTECTED
Lisfinity Core - Lisfinity Core plugin used for pebas Lisfinity WordPress theme (Privilege Escalation) < 1.5.0
14 Oct 2025
PROTECTED
Dynamically Display Posts (Unauthenticated SQL Injection) < 1.2
14 Oct 2025
PROTECTED
Flex QR Code Generator (Arbitrary File Upload)
14 Oct 2025
PROTECTED
Demo Import Kit (Arbitrary File Upload)
14 Oct 2025
PROTECTED
Outdoor (Unauthenticated SQL Injection) < 1.3.3
14 Oct 2025
PROTECTED
WPBifrst - Instant Passwordless Temporary Login Links (Missing Authorization to Privilege Escalation) < 1.0.8
14 Oct 2025
PROTECTED
Orion SMS OTP Verification (Authentication Bypass via Account Takeover)
14 Oct 2025
PROTECTED
Category and Products Accordion Panel (Local File Inclusion via Shortcode) < 1.1
14 Oct 2025
PROTECTED
Find And Replace content for WordPress (Missing Authorization)
14 Oct 2025
PROTECTED
DocoDoco Store Locator (Arbitrary File Upload)
14 Oct 2025
PROTECTED