Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
47,664
Mitigations
Mitigation rules
15,355
No official patch
12,999
In triage
1,511
Published soon
80
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
<= 2.0.8
SQL Injection vulnerability
8.5
04/06/2026
Sunshine Photo Cart
<= 3.6.7
Broken Access Control vulnerability
6.3
02/06/2026
SePay Gateway
<= 1.1.20
Sensitive Data Exposure vulnerability
6.5
02/06/2026
The Post Grid
<= 7.9.2
Broken Access Control vulnerability
4.3
6 hours ago
ElementsKit Elementor addons Lite
<= 3.9.6
Broken Access Control vulnerability
5.3
6 hours ago
ElementsKit Elementor addons Lite
<= 3.9.6
Broken Access Control vulnerability
4.3
6 hours ago
WP Meta and Date Remover
<= 2.3.6
Broken Access Control vulnerability
4.3
6 hours ago
DearFlip
<= 2.4.27
Broken Access Control vulnerability
4.3
7 hours ago
Duplicate Page and Post
<= 2.9.5
SQL Injection vulnerability
8.5
7 hours ago
Advanced Custom Fields: Font Awesome Field
<= 5.0.2
Cross Site Scripting (XSS) vulnerability
6.5
7 hours ago
Adminimize
<= 1.11.11
Broken Access Control vulnerability
4.3
7 hours ago
Facebook for WooCommerce
<= 3.7.0
Open Redirection vulnerability
4.7
7 hours ago
SVG Support
<= 2.5.14
Broken Access Control vulnerability
4.3
7 hours ago
SeedProd Pro
< 6.19.5
Local File Inclusion vulnerability
7.5
8 hours ago
Product Import Export for WooCommerce
<= 2.5.6
Broken Access Control vulnerability
4.3
9 hours ago
Advanced Custom Fields
<= 6.8.1
Unauthenticated Broken Access Control vulnerability
5.3
12 hours ago
affiliate-toolkit
<= 3.8.4
Authenticated (Editor+) Remote Code Execution vulnerability
7.2
12 hours ago
Booking Calendar – Event Calendar
<= 2.1.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
12 hours ago
Query Shortcode
<= 0.2.1
Authenticated (Contributor+) Local File Inclusion vulnerability
7.5
12 hours ago
NS Product icon badge
<= 1.2.4
Reflected Cross-Site Scripting vulnerability
6.1
12 hours ago
Load more