
CVE-2026-78070
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

Proof-of-concept exploit for CVE-2025-2011, a SQL injection vulnerability in WordPress Depicter Plugin 3.6.1, enabling database enumeration and data…

Proof-of-concept exploit for CVE-2024-33911, a post-authenticated SQL injection vulnerability in The School Management WordPress plugin v10.3.4,…

RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Woo Inquiry <= 0.1 - Unauthenticated SQL Injection

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'

exploit SQL injection ELEX WooCommerce Google Shopping