CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

The Hack Repair Guy's Plugin Archiver (Arbitrary File Deletion) < 3.1.1
12 Sep 2025
PROTECTED
LWS Cleaner (Arbitrary File Deletion) < 2.4.2
11 Sep 2025
PROTECTED
The Events Calendar (Unauthenticated SQL Injection) < 6.15.1.1
11 Sep 2025
PROTECTED
Catalog Importer, Scraper & Crawler (Unauthenticated PHP Code Injection)
10 Sep 2025
PROTECTED
All in one Minifier (Unauthenticated SQL Injection) < 3.3
10 Sep 2025
PROTECTED
Ultimate Classified Listings (Local File Inclusion)
10 Sep 2025
PROTECTED
My WP Translate (Arbitrary Options Update)
10 Sep 2025
PROTECTED
Propovoice (Unauthenticated Arbitrary File Read) < 1.7.8
10 Sep 2025
PROTECTED
Time Tracker (Arbitrary Options Update and Limited Data Deletion) < 3.2.0
10 Sep 2025
PROTECTED
Import any XML, CSV or Excel File to WordPress (Unsafe File Upload) < 3.9.4
9 Sep 2025
PROTECTED
Resideo Plugin for Resideo - Real Estate WordPress Theme (Privilege Escalation)
9 Sep 2025
PROTECTED
WP Import - Ultimate CSV XML Importer for WordPress (Missing Authorization to FTP/SFTP Credential Exposure) < 7.28
9 Sep 2025
PROTECTED
Responsive Filterable Portfolio (Arbitrary File Upload) < 1.0.25
9 Sep 2025
PROTECTED
Doccure (Arbitrary File Upload) < 1.4.9
8 Sep 2025
PROTECTED
Doccure (Unauthenticated Arbitrary File Upload) < 1.4.9
8 Sep 2025
PROTECTED
Doccure (Arbitrary User Password Change)
8 Sep 2025
PROTECTED
AutomatorWP - Automator plugin for no-code automations, webhooks & custom integrations in WordPress (Remote Code Execution) < 5.3.7
8 Sep 2025
PROTECTED
Goza - Nonprofit Charity WordPress Theme (Unauthenticated Arbitrary File Upload) < 3.2.3
8 Sep 2025
PROTECTED
AdForest (Authentication Bypass to Admin) < 6.0.10
5 Sep 2025
PROTECTED
Multi Step Form (Arbitrary File Upload) < 1.7.26
5 Sep 2025
PROTECTED