CROWD-SOURCED
VULNERABILITIES DATABASE

Vulnerabilities Crowdsourced from WordPress security researchers and the amazing public databases of –

BoomBox Theme Extensions (Privilege Escalation) < 1.8.1
18 Mar
PROTECTED
s2Member Pro (Local File Inclusion)
18 Mar
PROTECTED
MinimogWP - Theme (Unauthenticated Local PHP File Inclusion) < 3.8.0
18 Mar
PROTECTED
Altair (Unauthenticated Arbitrary Options Update) < 5.2.5
18 Mar
PROTECTED
Service Finder Bookings (Unauthenticated Privilege Escalation via Account Takeover) < 5.1
18 Mar
PROTECTED
CozyStay (Unauthenticated PHP Object Injection) < 1.7.1
18 Mar
PROTECTED
GetShop ecommerce (Unauthenticated Local File Inclusion)
17 Mar
PROTECTED
LinkedIn Lite (Unauthenticated Local File Inclusion)
17 Mar
PROTECTED
Custom Field List Widget (Unauthenticated Local File Inclusion)
17 Mar
PROTECTED
Realteo - Real Estate Plugin by Purethemes (Authentication Bypass via 'do_register_user') < 1.2.9
13 Mar
PROTECTED
CiyaShop - Multipurpose WooCommerce Theme (Unauthenticated PHP Object Injection) < 4.19.1
13 Mar
PROTECTED
WP JobHunt (Unauthenticated Privilege Escalation)
13 Mar
PROTECTED
Industrial (Arbitrary Options Update) < 1.7.9
13 Mar
PROTECTED
Civi - Job Board & Freelance Marketplace WordPress Theme (Sensitive Information Exposure)
13 Mar
PROTECTED
SoundRise Music (Arbitrary Options Update) < 1.7.1
13 Mar
PROTECTED
InstaWP Connect (Cross-Site Request Forgery to Local File Inclusion) < 0.1.0.84
13 Mar
PROTECTED
AnalyticsWP (Unauthenticated SQL Injection) < 2.1.0
13 Mar
PROTECTED
All in One WP Migration (Unauthenticated PHP Object Injection) < 7.90
12 Mar
PROTECTED
Workreap (Unauthenticated Privilege Escalation) < 3.2.6
11 Mar
PROTECTED
HUSKY - Products Filter Professional for WooCommerce (Unauthenticated Local File Inclusion) < 1.3.6.6
10 Mar
PROTECTED