Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,348
Mitigations
Mitigation rules
17,070
No official patch
13,360
In triage
1,352
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@platejs/core
< 53.3.11
NPM: @platejs/core HTML deserialization can trigger browser behavior during parsing
6.1
1 hour ago
devalue
< 5.9.1
NPM: Svelte devalue: DoS via malformed input
5.3
1 hour ago
@libp2p/peer-store
>= 8.0.0, < 12.0.24
NPM: libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
8.2
4 hours ago
@libp2p/gossipsub
>= 15.0.0, < 16.0.5
NPM: libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
7.5
4 hours ago
exifreader
<= 4.41.0
Memory Exhaustion
7.5
5 hours ago
CheckView Automated Testing
< 2.3.2
Administrator Account Creation via REST API Authentication Bypass vulnerability
9.8
6 hours ago
Custom Fields
< 1.5.1
Unauthenticated Arbitrary File Deletion via Path Traversal vulnerability
8.6
6 hours ago
Single Sign On For TNG
< 2.2.0
Unauthenticated Arbitrary Password Reset vulnerability
9.8
6 hours ago
Dataverse Integration
< 2.91
Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure vulnerability
4.3
6 hours ago
WP Events Manager
< 2.2.5
Unauthenticated Payment Bypass and Booking Status Update via IDOR vulnerability
5.3
6 hours ago
Five Star Restaurant Reservations
< 2.7.23
Unauthenticated Payment Bypass and Booking Confirmation via IDOR vulnerability
5.3
6 hours ago
Ninja Forms
< 3.14.10
Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default vulnerability
5.3
6 hours ago
miniOrange's Google Authenticator
< 6.2.7
2FA Bypass via Password-Only Second-Factor Rebinding vulnerability
4.3
6 hours ago
Contest Gallery
< 30.0.7
Unauthenticated Login-Protection and 2FA Bypass via post_cg_login vulnerability
4.8
6 hours ago
Event Booking Manager for WooCommerce (Pro)
<= 5.0.2
Unauthenticated Price Manipulation vulnerability
5.3
6 hours ago
Newsletters
< 4.16
Unauthenticated API Authentication Bypass via Type Juggling vulnerability
4.8
6 hours ago
Easy Booking – WooCommerce Booking & Reservation Plugin
< 3.5.0
Unauthenticated Minimum Booking Duration Bypass vulnerability
5.3
6 hours ago
WordPress File Upload
< 5.1.7
File Overwrite via Race Condition vulnerability
5.4
6 hours ago
Contact Form by WPForms
< 1.10.0.5
Unauthenticated PayPal Webhook Forgery vulnerability
5.3
6 hours ago
@tinacms/auth
<= 1.1.3
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
7 hours ago
Load more