The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,734
Mitigations14,826
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
pz-frontend-manager<= 1.0.6
Missing Authorization to Arbitrary User Deletion via 'dataType' Parameter vulnerability
5.3
48 minutes ago
AM LottiePlayer<= 3.6.0
Authenticated (Author+) Stored Cross-Site Scripting via SVG vulnerability
5.9
56 minutes ago
Sports Club Management<= 1.12.9
Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' Attribute vulnerability
6.5
58 minutes ago
Columns by BestWebSoft<= 1.0.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'columns' Shortcode 'id' Attribute vulnerability
6.5
59 minutes ago
Quran Translations<= 1.7
Cross-Site Request Forgery to Playlist Settings Form vulnerability
4.3
1 hour ago
Riaxe Product Customizer<= 2.4
Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint vulnerability
5.3
1 hour ago
Gerador de Certificados – DevApps<= 1.3.6
WordPress Gerador de Certificados - DevApps plugin <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload vulnerability
7.2
3 hours ago
Wavr<= 0.2.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
3 hours ago
WowPress<= 1.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
3 hours ago
Inquiry form to posts or pages<= 1.0
Authenticated (Administrator+) Stored Cross-Site Scripting via Form Header Field vulnerability
5.9
3 hours ago
The Plus Addons for Elementor Page Builder Lite<= 6.4.9
WordPress The Plus Addons for Elementor - Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar vulnerability
6.5
3 hours ago
Backup Migration<= 2.0.0
Missing Authorization to Unauthenticated Backup Upload to Offline Storage vulnerability
5.3
3 hours ago
Investi<= 1.0.26
Authenticated (Contributor+) Stored Cross-Site Scripting via 'maximum-num-years' Shortcode Attribute vulnerability
6.5
3 hours ago
Strong Testimonials<= 3.2.21
Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode vulnerability
6.5
3 hours ago
TableOn<= 1.0.4.4
WordPress TableOn - WordPress Posts Table Filterable plugin <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute vulnerability
6.5
3 hours ago
LTL Freight Quotes – R+L Carriers Edition<= 3.3.13
WordPress LTL Freight Quotes - R+L Carriers Edition plugin <= 3.3.13 - Missing Authorization to Unauthenticated Settings Update vulnerability
5.3
3 hours ago
MainWP Child Reports<= 2.2.6
Missing Authorization to Authenticated (Subscriber+) Information Disclosure via Heartbeat API vulnerability
5.3
3 hours ago
Prime Slider – Addons For Elementor<= 4.1.10
Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter vulnerability
5.9
3 hours ago
LearnPress<= 4.3.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute vulnerability
6.5
3 hours ago
LatePoint<= 5.3.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
3 hours ago