The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,963
Mitigations16,976
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WP Express Checkout (Accept PayPal Payments)< 2.5.0
Unauthenticated Payment Bypass vulnerability
5.3
3 hours ago
Spam protection, AntiSpam, FireWall by CleanTalk< 6.87
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
3 hours ago
SupportCandy3.2.9-3.5.2
Unauthenticated Ticket Attachment Disclosure vulnerability
5.3
3 hours ago
Payment Plugins for PayPal WooCommerce< 2.0.26
Subscriber+ Stored Payment Method Assignment vulnerability
5.9
3 hours ago
iTracker360<= 2.2.0
Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field vulnerability
6.1
3 hours ago
Quentn WP1.2.13-1.2.14
Unauthenticated SQLi vulnerability
9.3
3 hours ago
Loops & Logic< 4.3.0
Unauthenticated User Data and Site Option Disclosure vulnerability
7.5
3 hours ago
ELEX WooCommerce Request a Quote< 2.4.1
Unauthenticated SQLi vulnerability
9.3
3 hours ago
Chat Help<= 3.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
7.5
4 hours ago
Business Intelligence Lite<= 3.2.0
Authenticated (Subscriber+) Missing Authorization to Privilege Escalation vulnerability
8
4 hours ago
Direct Download for WooCommerce<= 1.19
Unauthenticated Arbitrary File Read vulnerability
7.5
4 hours ago
Bulk Password Reset<= 1.3.3
Authenticated (Subscriber+) Arbitrary Password Reset vulnerability
8.8
4 hours ago
@openhop/server<= 0.3.5
NPM: @openhop/server: Path Traversal in Flow ID File Operations
8.3
11 hours ago
functype-mcp-server<= 1.4.3
NPM: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
7.8
11 hours ago
@yeger/turbo-graph<= 2.8.8
NPM: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
8.8
11 hours ago
nuxt-ollama>= 1.2.26, < 1.3.1
NPM: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
7.5
11 hours ago
Aruba HiSpeed Cache<= 3.0.14
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
smol-toml<= 1.7.0
NPM: smol-toml: Denial of Service via malformed TOML documents
8.2
16 hours ago
Easy Google Fonts<= 2.0.4
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
6.5
19 hours ago
Advanced Contact form 7 DB<= 2.1.3
Missing Authorization to Authenticated (Custom+) Unauthorized Data Import vulnerability
4.3
19 hours ago