CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

WPC Admin Columns (Privilege Escalation) < 2.1.1
11 Apr
PROTECTED
WPC Admin Columns (Privilege Escalation) < 2.1.1
11 Apr
PROTECTED
SMTP for Amazon SES (Stored Cross Site Scripting) < 1.9
10 Apr
PROTECTED
InstaWP Connect (Local PHP File Inclusion) < 0.1.0.86
10 Apr
PROTECTED
Embedder(Arbitrary Options Update)
9 Apr
PROTECTED
azurecurve Shortcodes in Comments (Arbitrary Shortcode Execution)
9 Apr
PROTECTED
ORDER POST (Arbitrary Shortcode Execution)
9 Apr
PROTECTED
SureTriggers (Missing Empty Value Check) < 1.0.79
9 Apr
PROTECTED
Streamit (Privilege Escalation) < 4.0.3
7 Apr
PROTECTED
Motors - Car Dealership & Classified Listings Plugin (Arbitrary Plugin Installation) < 1.4.65
7 Apr
PROTECTED
WPFront User Role Editor (Cross-Site Request Forgery to Privilege Escalation) < 4.2.2
7 Apr
PROTECTED
Simple WP Events (Unauthenticated Arbitrary File Deletion)
7 Apr
PROTECTED
ZoomSounds - WordPress Wave Audio Player with Playlist (Arbitrary File Download)
7 Apr
PROTECTED
Streamit (Privilege Escalation) < 4.0.3
7 Apr
PROTECTED
Drag and Drop Multiple File Upload for WooCommerce(Arbitrary File Move) < 1.1.5
4 Apr
PROTECTED
ZoomSounds WordPress Wave Audio Player with Playlist (Limited Options Update )
4 Apr
PROTECTED
Email Notifications for Updates (Arbitrary Options Update) < 1.2.0
4 Apr
PROTECTED
Streamit (Arbitrary File Upload) < 4.0.2
4 Apr
PROTECTED
Countdown, Coming Soon, Maintenance Countdown & Clock (Local File Inclusion) < 2.9.0
3 Apr
PROTECTED
Product Filter by WBW (SQL Injection) < 2.8.0
3 Apr
PROTECTED