The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total38,615
Mitigations14,168
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
ElementsKit Elementor addons Lite< 3.7.9
Unauthenticated Mailchimp REST Endpoint vulnerability
6.5
10 hours ago
The Plus Addons for Elementor Page Builder Lite<= 6.4.7
WordPress The Plus Addons for Elementor - Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin <= 6.4.7 - Unauthenticated Email Relay vulnerability
5.3
10 hours ago
Conditional CAPTCHA<= 4.0.0
Open Redirect vulnerability
4.7
10 hours ago
Ebook Store<= 5.8001
Reflected Cross-Site Scripting via 'step' vulnerability
7.1
14 hours ago
WP Ad Guru<= 2.5.4
Reflected Cross-Site Scripting vulnerability
7.1
15 hours ago
Simple Membership<= 4.7.0
Unauthenticated Improper Handling of Missing Values vulnerability
6.5
1 day ago
WP Customer Reviews<= 3.7.5
Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter vulnerability
7.1
1 day ago
Shield Security<= 21.0.8
Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter vulnerability
7.1
1 day ago
xmlrpc attacks blocker<= 1.0
Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' vulnerability
7.1
1 day ago
iXML<= 0.6
WordPress iXML - Google XML sitemap generator plugin <= 0.6 - Reflected Cross-Site Scripting via 'iXML_email' Parameter vulnerability
7.1
1 day ago
Easy Author Image<= 1.7
Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Picture URL vulnerability
6.5
1 day ago
Wholesale Suite<= 2.2.1
Privilege Escalation vulnerability
7.2
4 days ago
Woocommerce Wholesale Lead Capture<= 1.17.8
Privilege Escalation vulnerability
9.8
4 days ago
Woocommerce Wholesale Lead Capture<= 1.17.8
Arbitrary File Upload vulnerability
9
4 days ago
EventPrime<= 4.2.8.3
Sensitive Data Exposure vulnerability
5.3
4 days ago
Smartsupp – live chat, chatbots, AI and lead generation<= 3.9.1
WordPress Smartsupp - live chat, AI shopping assistant and chatbots plugin <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
4 days ago
WooCommerce Checkout Manager<= 7.8.1
Unauthenticated Limited File Upload vulnerability
5.3
4 days ago
Aruba HiSpeed Cache<= 3.0.2
Missing Authorization to Unauthenticated Plugin's Settings Modification vulnerability
6.5
4 days ago
Ads Pro<= 5.0
Broken Access Control vulnerability
5.4
4 days ago
Aruba HiSpeed Cache<= 3.0.2
Reflected Cross-Site Scripting vulnerability
7.1
4 days ago