Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,789
Mitigations
Mitigation rules
17,239
No official patch
13,366
In triage
1,348
Published soon
64
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Knit Pay
<= 9.6.1.0
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Wawp
<= 4.8.6
Unauthenticated Privilege Escalation vulnerability
9.8
2 hours ago
s2Member
<= 260814
Unauthenticated Remote Code Execution vulnerability
8.8
2 hours ago
Optima Express + MarketBoost IDX Plugin
<= 8.7.5
Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment vulnerability
7.3
2 hours ago
cline
< 3.0.30
NPM: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
8.8
4 hours ago
@rsdoctor/rspack-plugin
<= 1.5.15
NPM: @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
7.5
4 hours ago
@bytebase/dbhub
< 0.22.6
NPM: @bytebase/dbhub's read-only mode does not prevent database writes
7.4
4 hours ago
@bytebase/dbhub
<= 0.22.4
NPM: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
9.3
4 hours ago
xhtml-purifier
<= 0.4.1
NPM: xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
6.1
4 hours ago
@bsv/wallet-toolbox
>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
@bsv/wallet-toolbox-client
>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
@bsv/wallet-toolbox-mobile
>= 1.3.21, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
4 hours ago
cyberchef
< 11.2.0
NPM: CyberChef: Prototype pollution in Series Chart operation
5
4 hours ago
@aws/lsp-codewhisperer
< 0.0.117
NPM: Language Servers for AWS vulnerable to arbitrary file write
7.8
4 hours ago
@aws/lsp-codewhisperer
< 0.0.113
NPM: Language Servers for AWS Vulnerable to Arbitrary Code Execution
8.5
4 hours ago
suneditor
<= 2.47.10
sanitizer bypass
10
8 hours ago
King Addons for Elementor
<= 51.1.85
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Pixel Manager for WooCommerce
<= 1.69.0
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Business Directory
<= 6.4.27
Insecure Direct Object References (IDOR) vulnerability
5.4
13 hours ago
The Plus Addons for Elementor Page Builder Lite
<= 6.5.1
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Load more