Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,901
Mitigations
Mitigation rules
16,582
No official patch
13,325
In triage
1,070
Published soon
95
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
gettext-converter
< 1.3.3
NPM: gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
6.9
18 minutes ago
@nocobase/server
< 2.1.5
NPM: NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
0
1 hour ago
@whyour/qinglong
< 2.20.1
NPM: Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
9.3
1 hour ago
node-opcua
<= 2.165.0
NPM: node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
7.5
1 hour ago
node-opcua
<= 2.165.0
NPM: node-opcua missing nonce verification in UserNameIdentityToken authentication
7.7
1 hour ago
next-video
<= 2.8.0
NPM: next-video: Unauthenticated arbitrary file read via /api/video request handler
6.9
1 hour ago
@nocobase/plugin-backups
< 2.1.19
NPM: NocoBase backup restore schema name allows command injection
6.7
1 hour ago
Easy Elementor Addons
<= 2.3.7
Cross Site Request Forgery (CSRF) vulnerability
9.6
7 hours ago
New User Approve
<= 3.2.8
Broken Access Control vulnerability
5.3
7 hours ago
InfiniteWP Client
<= 1.13.9
SQL Injection vulnerability
7.6
7 hours ago
TranslatePress
<= 3.2.5
WordPress TranslatePress - Translate Multilingual sites with AI Translation plugin <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
EWWW Image Optimizer
<= 8.7.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content vulnerability
6.5
9 hours ago
WP Statistics
<= 14.16.8
Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter vulnerability
7.1
9 hours ago
Atarim
<= 5.1.1
Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta vulnerability
8.1
9 hours ago
TrueBooker
<= 1.2.6
Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter vulnerability
9.8
9 hours ago
Speed Optimizer
<= 7.8.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes vulnerability
6.5
9 hours ago
PPWP
<= 1.9.15
Improper Authorization To Authenticated (Contributor+) Master Password Exposure vulnerability
4.3
9 hours ago
Tourmaster
< 5.4.9
Unauthenticated Sensitive Data Disclosure via Order Export vulnerability
5.3
9 hours ago
Vitepos
< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
9 hours ago
Vitepos
< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
9 hours ago
Load more