Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,524
Mitigations
Mitigation rules
16,391
No official patch
13,264
In triage
1,147
Published soon
13
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Forminator
<= 1.56.1
Unauth. Arbitrary File Upload
9.8
01/01/2100
vm2
<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
13 minutes ago
vm2
<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
13 minutes ago
vm2
<= 3.11.5
NPM: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
9.8
13 minutes ago
vm2
<= 3.11.5
NPM: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
9.9
13 minutes ago
vm2
<= 3.11.5
NPM: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
8.7
14 minutes ago
Gravity Booster – Styles & Layouts for Gravity Forms
<= 6.0
Broken Access Control vulnerability
5.4
29 minutes ago
RomethemeForm For Elementor
<= 1.2.6
Broken Access Control vulnerability
4.3
29 minutes ago
WP Table Builder
<= 2.2.0
Broken Access Control vulnerability
4.3
34 minutes ago
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery
<= 1.16.20
Sensitive Data Exposure vulnerability
5.3
35 minutes ago
Shortcodes and extra features for Phlox theme
<= 2.17.22
Sensitive Data Exposure vulnerability
5.3
36 minutes ago
Razorpay for WooCommerce
<= 4.8.7
Insecure Direct Object References (IDOR) vulnerability
5.3
37 minutes ago
@medplum/core
<= 5.1.5
NPM: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
7.1
4 hours ago
deepmerge-ts
< 8.0.0
NPM: DeepmergeTS has stack exhaustion when merging recursive object graphs
8.2
4 hours ago
TrueBooker
<= 1.2.6
Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter vulnerability
9.8
5 hours ago
Wholesale Market
<= 2.2.2
Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter vulnerability
8.8
5 hours ago
KiviCare
<= 4.5.1
Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter vulnerability
8.5
6 hours ago
Groundhogg
<= 4.5.14
Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter vulnerability
8.5
6 hours ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
<= 5.1
Unauthenticated Stored Cross-Site Scripting via 'action' Parameter vulnerability
7.1
6 hours ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
<= 5.1
Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values vulnerability
7.6
6 hours ago
Load more