Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,597
Mitigations
Mitigation rules
16,863
No official patch
13,334
In triage
1,093
Published soon
37
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
RegistrationMagic
< 6.0.9.9
Unauthenticated Stored XSS vulnerability
7.1
7 minutes ago
Rank Math SEO
< 1.0.277
Author+ Robots and Pillar Content Meta Update on Non-Owned Objects vulnerability
2.7
13 minutes ago
GamiPress
< 7.9.9.6
Subscriber+ Arbitrary User Points and Achievement Award vulnerability
4.3
13 minutes ago
Social Media & Share Icons
< 3.0.1
Reflected XSS vulnerability
7.1
14 minutes ago
Photo Gallery by 10Web
< 1.8.44
Reflected XSS vulnerability
7.1
20 minutes ago
Backup Guard
3.1.7.9-3.1.23.3
Subscriber+ Privilege Escalation vulnerability
7.1
32 minutes ago
ACF Extended
< 0.9.2.7
Unauthenticated Administrator Account Takeover vulnerability
8.1
43 minutes ago
ACF Extended
0.9.2.2-0.9.2.6
Unauthenticated Privilege Escalation vulnerability
8.1
50 minutes ago
@dicebear/core
<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
7 hours ago
@dicebear/initials
<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
7 hours ago
@platejs/docx-io
< 53.3.2
NPM: Plate: SSRF with response disclosure in DOCX image embedding
8.2
8 hours ago
link-preview-js
<= 4.0.3
NPM: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
7.5
9 hours ago
Divi
<= 4.27.6
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
10 hours ago
GutenKit
<= 2.4.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
fast-uri
>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
14 hours ago
fast-uri
>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
14 hours ago
fast-uri
>= 2.4.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
7.5
15 hours ago
fast-uri
>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to host confusion via percent-encoded scheme normalization
7.5
15 hours ago
@xmldom/xmldom
>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
15 hours ago
xmldom
<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
15 hours ago
Load more