The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,630
Mitigations14,793
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
FloristPress<= 7.8.2
Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability
7.1
1 hour ago
JS Help Desk<= 3.0.4
WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability
9.3
1 hour ago
SureForms<= 2.5.2
Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
7.5
2 hours ago
Masteriyo - LMS<= 2.1.6
Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability
8.8
2 hours ago
Responsive Plus< 3.4.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
2 hours ago
WP Job Portal<= 2.4.9
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
8.8
2 hours ago
ThemeREX Addons< 2.38.5
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
Download Monitor<= 5.1.7
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
5.3
3 hours ago
Twentig Supercharged Block Editor<= 1.9.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability
6.5
3 hours ago
WP Lightbox 2< 3.0.7
Admin+ Stored XSS vulnerability
5.9
3 hours ago
Conditional Menus<= 1.2.6
Cross-Site Request Forgery to Menu Options Update vulnerability
4.3
3 hours ago
Complianz<= 7.4.4.2
WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
6.5
3 hours ago
Elementor Website Builder<= 3.35.7
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
4.3
3 hours ago
Ads by WPQuads<= 2.0.98.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Ad Metadata Parameters vulnerability
6.5
2 days ago
PageLayer<= 2.0.7
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
5.3
2 days ago
Ninja Forms<= 3.14.1
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
6.5
2 days ago
Amelia<= 9.1.2
Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability
8.8
2 days ago
DSGVO snippet for Leaflet Map and its Extensions<= 3.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability
6.5
2 days ago
FormLift for Infusionsoft Web Forms<= 7.5.21
Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow vulnerability
5.3
2 days ago
Blog2Social<= 8.8.2
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability
4.3
2 days ago