CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

Better Find and Replace (Limited Code Injection) < 1.7.8
7 Nov 2025
PROTECTED
Smart Auto Upload Images (Arbitrary File Upload) < 1.2.1
7 Nov 2025
PROTECTED
Asgaros Forum (Unauthenticated SQL Injection) < 3.2.0
7 Nov 2025
PROTECTED
Mail Mint (Arbitrary File Upload) < 1.18.11
7 Nov 2025
PROTECTED
Alex Reservations: Smart Restaurant Booking (Arbitrary File Upload) < 2.2.4
7 Nov 2025
PROTECTED
LC Wizard (Unauthenticated Privilege Escalation) < 1.4.0
6 Nov 2025
PROTECTED
IDonate (Privilege Escalation) < 2.1.10
6 Nov 2025
PROTECTED
The Events Calendar (Unauthenticated SQL Injection via s) < 6.15.10
4 Nov 2025
PROTECTED
Document Embedder - Embed PDFs, Word, Excel, and Other Files (Missing Authorization to Unauthenticated Document Manipulation) < 2.0.1
4 Nov 2025
PROTECTED
Premium Portfolio Features for Phlox theme (Unauthenticated Local File Inclusion) < 2.3.12
4 Nov 2025
PROTECTED
Easy Upload Files During Checkout (Unauthenticated Arbitrary JavaScript File Upload) < 2.9.9
3 Nov 2025
PROTECTED
CE21 Suite (Missing Authorization to Unauthenticated Privilege Escalation) < 2.3.2
3 Nov 2025
PROTECTED
Crypto Payment Gateway with Payeer for WooCommerce (Unauthenticated Payment Bypass) < 1.0.4
3 Nov 2025
PROTECTED
Clubmember (Stored Cross-Site Scripting)
3 Nov 2025
PROTECTED
Footnotes Made Easy (Unauthenticated Stored Cross-Site Scripting) < 3.0.8
3 Nov 2025
PROTECTED
Booking and Rental Manager (Unauthenticated Stored Cross-Site Scripting) < 2.5.4
1 Nov 2025
PROTECTED
Advanced Ads (Unauthenticated Limited Code Execution) < 2.0.13
31 Oct 2025
PROTECTED
Tablesome Table - Contact Form DB - WPForms, CF7, Gravity, Forminator, Fluent (Unauthenticated Arbitrary File Upload) < 1.3.33
31 Oct 2025
PROTECTED
Kallyas (Remote Code Execution)
31 Oct 2025
PROTECTED
WPCOM Member (Local File Inclusion via Shortcode) < 1.7.15
31 Oct 2025
PROTECTED