CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

GutenKit (Arbitrary File Upload) < 2.1.1
10 Oct 2024
PROTECTED
Hunk Companion (Arbitrary Plugin Installation) < 1.8.5
10 Oct 2024
PROTECTED
Test Plugin - RevPluginRemoveaction < 2.1
4 Oct 2024
PROTECTED
Test Plugin - RevPluginRemovefilter < 3.1
4 Oct 2024
PROTECTED
Rank Math SEO (PHP Object Injection) < 1.0.229
4 Oct 2024
PROTECTED
Test Plugin - RevPlugin < 2.1.1
3 Oct 2024
PROTECTED
Social Web Suite (Arbitrary File Download) < 4.1.12
2 Oct 2024
PROTECTED
WP Hotel Booking (Arbitrary File Upload) < 2.1.3
1 Oct 2024
PROTECTED
WP Easy Gallery (SQL Injection)
30 Sep 2024
PROTECTED
Unseen Blog (PHP Object Injection)
30 Sep 2024
PROTECTED
Wechat Social login (Authentication Bypass)
30 Sep 2024
PROTECTED
REST API TO MiniProgram (SQL Injection)
25 Sep 2024
PROTECTED
The Events Calendar (SQL Injection) < 6.6.4.1
24 Sep 2024
PROTECTED
Prisna GWT (PHP Object Injection) < 1.4.12
24 Sep 2024
PROTECTED
Daily Prayer Time (SQL Injection) < 2024.09.14
24 Sep 2024
PROTECTED
WordPress Simple HTML Sitemap (SQL Injection) < 3.2
24 Sep 2024
PROTECTED
Advanced File Manager (Local File Inclusion) < 5.2.9
24 Sep 2024
PROTECTED
WP Easy Gallery (SQL Injection)
23 Sep 2024
PROTECTED
Easy Digital Downloads (PHAR Deserialization) < 3.3.4
23 Sep 2024
PROTECTED
Donation Forms by Charitable (Privilege Escalation) < 1.8.1.15
23 Sep 2024
PROTECTED