Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,146
Mitigations
Mitigation rules
17,042
No official patch
13,350
In triage
1,263
Published soon
2
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
AI Engine
<= 3.7.7
Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter vulnerability
6.5
5 hours ago
WP Event SOlution
<= 4.1.23
WordPress Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce plugin <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter vulnerability
7.5
5 hours ago
WP Event SOlution
<= 4.1.23
Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter vulnerability
6.5
6 hours ago
PublishPress Authors
<= 4.15.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
11 hours ago
ShopEngine
<= 4.9.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
Amelia
< 2.4.10
Amelia Manager+ WordPress Account Takeover vulnerability
7.2
12 hours ago
Export & Import WPBakery Page Builder
<= 1.0.2
CSRF to Stored XSS vulnerability
7.1
14 hours ago
Amelia
9.0-9.8.0
Unauthenticated Payment Bypass vulnerability
5.3
14 hours ago
Temporary Login Without Password
< 1.9.9
Authenticated Temporary Access Revocation Bypass vulnerability
5.5
14 hours ago
YayPricing
< 3.5.7
Subscriber+ Stored XSS vulnerability
6.5
14 hours ago
User Registration
< 5.2.8
Author+ Privilege Escalation to Administrator vulnerability
7.2
14 hours ago
GenieWords
1.5.27-1.5.34
Unauthenticated Stored XSS and Configuration Overwrite vulnerability
7.1
14 hours ago
YouTube Embed - YouTube Gallery, Vimeo Gallery - Wordpress Plugin
10.0-10.3
Unauthenticated Stored XSS vulnerability
7.1
14 hours ago
BE REST Endpoints
<= 1.0.0
Unauthenticated Stored XSS and Widget Manipulation vulnerability
7.1
14 hours ago
Hoo Companion
1.0.2
Unauthenticated Stored XSS vulnerability
7.1
14 hours ago
Rox Appointment Booking – Appointment Booking Scheduling Solution
< 1.2.0
Unauthenticated Holiday Schedule Modification vulnerability
6.5
14 hours ago
Rox Appointment Booking – Appointment Booking Scheduling Solution
< 1.2.0
Unauthenticated Price Manipulation and Payment Method Restriction Bypass vulnerability
5.3
14 hours ago
Simple Membership
< 4.7.8
Subscriber+ Membership Level Escalation vulnerability
5.4
14 hours ago
Mobile Events Manager
<= 1.4.8.3
Broken Access Control vulnerability
7.5
14 hours ago
Mobile DJ Manager
< 1.7.8.5
Unauthenticated Arbitrary Post Deletion vulnerability
7.5
14 hours ago
Load more