Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,176
Mitigations
Mitigation rules
16,677
No official patch
13,326
In triage
1,084
Published soon
44
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Royal Elementor Addons
< 1.7.1066
Contributor+ Stored XSS vulnerability
6.5
1 hour ago
Booking Package
< 1.7.25
Unauthenticated Price Manipulation vulnerability
5.3
1 hour ago
Royal Elementor Addons
< 1.7.1066
Unauthenticated Like Count and IP Meta Modification vulnerability
5.3
1 hour ago
Amelia
< 2.4.7
Unauthenticated Notification Queue Dispatch vulnerability
5.3
1 hour ago
Royal Elementor Addons
< 1.7.1066
Unauthenticated Taxonomy Term Disclosure vulnerability
5.3
1 hour ago
WPCafe
< 3.0.18
Unauthenticated Reservation Approval Bypass vulnerability
5.3
1 hour ago
WP Event SOlution
< 4.1.22
Unauthenticated Unpublished Content Disclosure vulnerability
5.3
1 hour ago
Betheme
<= 28.4
Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode vulnerability
6.5
12 hours ago
Gutenverse
<= 4.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks vulnerability
6.5
12 hours ago
Mailgun for WordPress
<= 2.2.0
Unauthenticated Server-Side Request Forgery (SSRF) vulnerability
7.2
12 hours ago
kk Star Ratings
<= 5.4.10.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
7.5
12 hours ago
@arikusi/deepseek-mcp-server
>= 1.4.2, < 1.8.0
NPM: @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
5.3
12 hours ago
@arikusi/deepseek-mcp-server
>= 1.4.2, < 1.7.0
NPM: @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
8.6
12 hours ago
consciousness-explorer
< 1.1.2
NPM: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
7.1
12 hours ago
sublinear-time-solver
< 1.6.0
NPM: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
7.1
12 hours ago
whistle
< 2.10.3
NPM: Whistle vulnerable to path traversal
8.7
12 hours ago
mediasoup
>= 3.20.0, <= 3.20.5
NPM: mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
5.6
13 hours ago
FundEngine
<= 1.8.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
Advanced Product Fields (Product Addons) for WooCommerce
<= 1.6.21
Unauthenticated Improper Input Validation to Price Bypass vulnerability
7.5
13 hours ago
WS Form LITE
<= 1.10.80
Unauthenticated PHP Object Injection vulnerability
9.8
13 hours ago
Load more