The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,612
Mitigations16,874
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Shared Files Pro< 1.7.70
Unauthenticated Arbitrary File Read vulnerability
7.5
5 hours ago
Simple Ajax Chat< 20260827
Unauthenticated Stored XSS vulnerability
7.1
5 hours ago
FAQ Builder AYS1.6.3-1.8.4
Unauthenticated Stored XSS vulnerability
7.1
5 hours ago
Theme My Login7.0-7.1.15
Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation vulnerability
5.4
5 hours ago
RegistrationMagic< 6.0.9.9
Unauthenticated Stored XSS vulnerability
7.1
5 hours ago
Rank Math SEO< 1.0.277
Author+ Robots and Pillar Content Meta Update on Non-Owned Objects vulnerability
2.7
6 hours ago
GamiPress< 7.9.9.6
Subscriber+ Arbitrary User Points and Achievement Award vulnerability
4.3
6 hours ago
Social Media & Share Icons< 3.0.1
Reflected XSS vulnerability
7.1
6 hours ago
Photo Gallery by 10Web< 1.8.44
Reflected XSS vulnerability
7.1
6 hours ago
Backup Guard3.1.7.9-3.1.23.3
Subscriber+ Privilege Escalation vulnerability
7.1
6 hours ago
ACF Extended< 0.9.2.7
Unauthenticated Administrator Account Takeover vulnerability
8.1
6 hours ago
ACF Extended0.9.2.2-0.9.2.6
Unauthenticated Privilege Escalation vulnerability
8.1
6 hours ago
@dicebear/core<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
13 hours ago
@dicebear/initials<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
13 hours ago
@platejs/docx-io< 53.3.2
NPM: Plate: SSRF with response disclosure in DOCX image embedding
8.2
14 hours ago
link-preview-js<= 4.0.3
NPM: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
7.5
15 hours ago
Divi<= 4.27.6
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
16 hours ago
GutenKit<= 2.4.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
20 hours ago
fast-uri>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
20 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
20 hours ago