Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,456
Mitigations
Mitigation rules
15,973
No official patch
13,050
In triage
1,416
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
astro
>= 2.9.0, <= 7.0.9
NPM: Astro: Reflected XSS via unescaped View Transition animation properties
5.3
14 minutes ago
@better-auth/sso
>= 1.2.10, < 1.6.11
NPM: @better-auth/sso: SSO provider may allow registration for any org member without a checking their role
7.1
16 minutes ago
brace-expansion
< 1.1.16
NPM: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
5.3
31 minutes ago
Essential Addons for Elementor
<= 6.6.11
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 hour ago
Tutor LMS Elementor Addons
<= 4.0.0
Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation vulnerability
4.3
1 hour ago
MapSVG
<= 8.14.0
Authenticated (Administrator+) Arbitrary File Upload vulnerability
9.1
1 hour ago
axios
>= 0.28.0, < 0.33.0
NPM: Axios: Excessive recursion in formDataToJSON can cause denial of service
6.3
3 hours ago
axios
>= 1.15.2, < 1.18.0
NPM: Axios: Prototype pollution auth subfields can inject Basic auth
6.3
3 hours ago
axios
>= 0.28.0, < 0.33.0
NPM: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
6.3
3 hours ago
Contact Form by WPForms
<= 2.0.0.1
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
4 hours ago
Essential Addons for Elementor
<= 6.6.11
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
5 hours ago
Spectra
<= 2.19.28
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
@tak-ps/cloudtak
< 13.10.0
NPM: CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
7.6
2 days ago
exifreader
<= 4.40.0
NPM: ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
5.3
3 days ago
@prompty/core
>= 2.0.0-alpha.1, < 2.0.0-beta.3
NPM: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
8.7
3 days ago
@prompty/core
<= 2.0.0-beta.1
NPM: Prompty: Arbitrary file read via file reference expansion
7.5
3 days ago
mcp-memory-keeper
< 0.13.0
NPM: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
6.2
3 days ago
@tak-ps/cloudtak
<= 13.5.0
NPM: TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
5
3 days ago
WordPress
<= 7.0.1
Unauthenticated REST API Batch Request Handler Confusion
9.1
3 days ago
WordPress
<= 7.0.1
Unauthenticated SQL Injection vulnerability
9.8
3 days ago
Load more