CVE
    
        2025
        
            - 
                
                    StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+) Arbitrary File Upload
                
                
                    
                
            
- 
                
                    StoreEngine Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+) Arbitrary File Download
                
                
                    
                
            
- 
                
                    Make Connector <= 1.5.10 - Authenticated (Admin+) Arbitrary File Upload
                
                
                    
                
            
- 
                
                    Download Plugin <= 2.2.8 - Authenticated (Admin+) Arbitrary File Upload via the dpwap_plugin_locInstall Function
                
                
                    
                
            
- 
                
                    AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o
                
                
                    
                
            
- 
                
                    Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload
                
                
                    
                
            
- 
                
                    Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via save_options
                
                
                    
                
            
- 
                
                    eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
                
                
                    
                
            
- 
                
                    eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Delete
                
                
                    
                
            
- 
                
                    eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Read
                
                
                    
                
            
- 
                
                    eMagicOne Store Manager for WooCommerce <= 1.2.5- Unauthenticated Arbitrary File Upload via set_file Task
                
                
                    
                
            
- 
                
                    Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save
                
                
                    
                
            
- 
                
                    Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save
                
                
                    
                
            
- 
                
                    Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file
                
                
                    
                
            
2024
        
            - 
                
                    All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection