CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Jupiter X Core (Unauthenticated PHP Object Injection via PHAR) < 4.8.12
25 Apr
PROTECTED
Service Finder Bookings (Unauthenticated Privilege Escalation) < 6.0
24 Apr
PROTECTED
Flynax Bridge (Unauthenticated Privilege Escalation via Password Update)
23 Apr
PROTECTED
Database Toolset (Unauthenticated Arbitrary File Deletion)
23 Apr
PROTECTED
My Tickets - Accessible Event Ticketing (Privilege Escalation) < 2.0.17
23 Apr
PROTECTED
Verification SMS with TargetSMS (Unauthenticated Limited Remote Code Execution)
23 Apr
PROTECTED
Xelion Webchat (Arbitrary Options Update)
23 Apr
PROTECTED
Greenshift (Arbitrary File Upload) < 11.4.6
21 Apr
PROTECTED
UrbanGo Membership (Unauthenticated Privilege Escalation) < 1.1
18 Apr
PROTECTED
AIHub (Unauthenticated Arbitrary File Upload) < 1.3.8
18 Apr
PROTECTED
WP Headers And Footers (Cross-Site Request Forgery to Arbitrary Options Update) < 3.1.2
18 Apr
PROTECTED
JobWP - Job Board, Job Listing, Career Page and Recruitment Plugin (Unauthenticated SQL Injection) < 2.4.0
18 Apr
PROTECTED
Debug log Manager (Cross-Site Scripting) < 2.3.5
18 Apr
PROTECTED
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast (Unauthenticated Arbitrary File Read) < 2.5
18 Apr
PROTECTED
I Draw (Arbitrary File Upload)
17 Apr
PROTECTED
WPAMS (Arbitrary File Upload)
17 Apr
PROTECTED
WPAMS (Privilege Escalation)
17 Apr
PROTECTED
Avatar (Arbitrary File Deletion)
17 Apr
PROTECTED
Ultimate Member User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin (Unauthenticated Blind SQL Injection) < 2.10.2
16 Apr
PROTECTED
WPC Admin Columns (Privilege Escalation) < 2.1.1
11 Apr
PROTECTED