The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,692
Mitigations13,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Devs CRM<= 1.1.8
Unauthenticated Information Expsoure vulnerability
5.3
16 minutes ago
Userback<= 1.0.15
Missing Authorization to Authenticated (Subscriber+) Plugin's Configuration Exposure vulnerability
5.4
17 minutes ago
Easy Theme Options<= 1.0
Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Import vulnerability
5.3
20 minutes ago
Eyewear prescription form<= 6.0.1
Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation vulnerability
5.3
21 minutes ago
SimpLy Gallery<= 3.3.0
Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification vulnerability
4.3
28 minutes ago
Redux Framework<= 4.5.8
Authenticated (Contributor+) Stored Cross-Site Scripting via data Parameter vulnerability
6.5
37 minutes ago
a3 Lazy Load<= 2.7.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
38 minutes ago
rtMedia for WordPress, BuddyPress and bbPress4.7.0-4.7.3
Missing Authorization to Unauthenticated Information Disclosure
3.7
39 minutes ago
Colibri Page Builder<= 1.0.335
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 hour ago
Kingcabs<= 1.1.9
Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter vulnerability
6.5
1 hour ago
YITH WooCommerce Quick View<= 2.7.0
Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode vulnerability
6.5
1 hour ago
Mavix Education<= 1.0
Missing Authorization to Authenticated (Subscriber+) 'Creativ Demo Importer' Plugin Activation vulnerability
4.3
1 hour ago
Header Footer Script Adder<= 2.0.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 hour ago
Emplibot<= 1.0.9
Authenticated (Admin+) Server-Side Request Forgery vulnerability
4.4
2 hours ago
HT Slider For Elementor<= 1.7.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
2 hours ago
404 Solution<= 3.1.0
Authenticated (Admin+) SQL Injection via 'filterText' Parameter vulnerability
7.6
2 hours ago
Design Import/Export<= 2.2
Authenticated (Administrator+) SQL Injection via XML File Import vulnerability
7.6
2 hours ago
HAPPY<= 1.0.9
Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Reply vulnerability
5.4
2 hours ago
Custom Post Type UI<= 1.18.1
Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter vulnerability
5.9
2 hours ago
Employee Spotlight<= 5.1.3
Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification vulnerability
5.3
2 hours ago