The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,835
Mitigations13,214
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Post Expirator<= 4.9.2
Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure vulnerability
4.3
6 hours ago
Elementor Website Builder<= 3.33.3
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path vulnerability
6.5
6 hours ago
Fancy Product Designer<= 6.4.8
Unauthenticated Full Path Disclosure via 'pdf' Parameter vulnerability
5.3
6 hours ago
Auto Featured Image (Auto Post Thumbnail)<= 4.2.1
Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification vulnerability
4.3
6 hours ago
Dokan Pro<= 4.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
6 hours ago
LearnPress<= 4.3.1
Missing Authorization to Unauthenticated Orders Statistics Exposure vulnerability
5.3
6 hours ago
Modula Image Gallery<= 2.13.3
Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification vulnerability
4.3
7 hours ago
OneSignal – Web Push Notifications<= 3.6.1
Missing Authorization to Unauthenticated Plugin Settings Update vulnerability
5.3
7 hours ago
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress<= 2.0.3
WordPress FluentAuth - Auth Security Plugin plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode vulnerability
6.5
7 hours ago
RegistrationMagic<= 6.0.6.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode vulnerability
6.5
7 hours ago
CC Child Pages<= 2.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'child_pages' Shortcode vulnerability
6.5
7 hours ago
User Registration<= 4.4.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
7 hours ago
Filebird<= 6.5.1
Missing Authorization to Authenticated (Author+) Global Folders Tampering vulnerability
4.3
8 hours ago
Lightweight Accordion<= 1.5.20
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
Elementor Addon Elements<= 1.14.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
HandL UTM Grabber<= 2.8.0
Reflected Cross-Site Scripting vulnerability
7.1
12 hours ago
JetWidgets For Elementor<= 1.0.20
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets vulnerability
6.5
13 hours ago
CountDown With Image or Video Background<= 1.5
SQL Injection vulnerability
8.5
2 days ago
Head Meta Data<= 20250327
Cross Site Scripting (XSS) vulnerability
5.9
2 days ago
Accordion Slider PRO<= 1.2
SQL Injection vulnerability
8.5
2 days ago