The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,710
Mitigations16,880
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Spam protection, AntiSpam, FireWall by CleanTalk<= 6.86
Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder vulnerability
7.1
2 minutes ago
Divi<= 4.27.6
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter vulnerability
6.5
6 minutes ago
Divi<= 4.27.6
Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter vulnerability
4.9
7 minutes ago
Hummingbird<= 3.21.0
WordPress Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN plugin <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log vulnerability
9
10 minutes ago
DearFlip<= 2.4.30
Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute vulnerability
6.5
12 minutes ago
Theme My Login<= 7.1.15
Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage vulnerability
4.3
12 minutes ago
MStore API<= 4.20.0
Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery vulnerability
9.8
13 minutes ago
DearFlip<= 2.4.30
Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML vulnerability
6.5
13 minutes ago
WP Social Chat<= 8.6.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box vulnerability
6.5
13 minutes ago
Welcart e-Commerce<= 2.12.1
Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback vulnerability
8.6
13 minutes ago
Events Manager<= 7.3.3
WordPress Events Manager - Calendar, Bookings, Tickets, and more! plugin <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes vulnerability
5.9
25 minutes ago
deepseek-tui>= 0.8.6, < 0.8.41
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
1 hour ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
1 hour ago
deepseek-tui>= 0.8.33, < 0.8.41
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
1 hour ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
1 hour ago
deepseek-tui>= 0.3.27, < 0.8.41
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
1 hour ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
1 hour ago
deepseek-tui>= 0.8.5, < 0.8.41
TOCTOU on DNS failure for DNS pinning
8.6
1 hour ago
codewhale>= 0.8.41, < 0.8.64
TOCTOU on DNS failure for DNS pinning
8.6
1 hour ago
deepseek-tui>= 0.8.32, < 0.8.41
NPM: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
7.5
1 hour ago