CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

TagDiv Composer (PHP Object Instantiation) < 5.4
3 Apr
PROTECTED
Uncanny Automator (Privilege Escalation) < 6.4.0
3 Apr
PROTECTED
Booster for WooCommerce (Arbitrary File Upload) < 7.2.5
3 Apr
PROTECTED
Vehica Core (Privilege Escalation) < 1.0.98
3 Apr
PROTECTED
Woffice (Authentication Bypass) < 5.4.22
3 Apr
PROTECTED
Woffice Core (Arbitrary File Upload) < 5.4.22
3 Apr
PROTECTED
Vehica Core (Privilege Escalation) < 1.0.98
3 Apr
PROTECTED
Testimonial Slider (PHP Object Injection) < 2.0.14
3 Apr
PROTECTED
Booking Calendar and Notification (Unauthenticated SQL Injection)
3 Apr
PROTECTED
Front-End-Only-Users (Unauthenticated Arbitrary File Upload)
1 Apr
PROTECTED
Shopper Approved Reviews (Missing Authorization to Authenticated)
1 Apr
PROTECTED
User Registration & Membership (Authentication Bypass) < 4.1.3
1 Apr
PROTECTED
Salon booking system (Authenticated Privilege Escalation)
1 Apr
PROTECTED
HTML Forms (Unauthenticated Stored Cross-Site Scripting) < 1.5.2
1 Apr
PROTECTED
WP Pro Real Estate 7 (Arbitrary File Upload) < 3.5.5
31 Mar
PROTECTED
Import Export Suite for CSV and XML Datafeed (Authenticated Arbitrary File Upload) < 7.19.1
31 Mar
PROTECTED
WP RealEstate (Authentication Bypass) < 1.6.27
31 Mar
PROTECTED
Booster for WooCommerce (Stored Cross-Site Scripting) < 7.2.6
31 Mar
PROTECTED
SMS Alert Order Notifications WooCommerce (Privilege Escalation) < 3.8.0
31 Mar
PROTECTED
Checkout Mestres do WP for WooCommerce (Unauthenticated Arbitrary Options Update) < 8.7.5.1
28 Mar
PROTECTED