Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,496
Mitigations
Mitigation rules
16,839
No official patch
13,331
In triage
1,127
Published soon
17
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
FluentCart
<= 1.6.2
Authenticated (Custom+) Arbitrary File Deletion vulnerability
7.7
16 minutes ago
WP Project Manager Pro
<= 4.0.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
37 minutes ago
Måne
<= 1.7
Unauthenticated Local File Inclusion vulnerability
8.1
48 minutes ago
WordPress Persistent Login
<= 3.1.0
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
52 minutes ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
<= 4.4.1
Unauthenticated Arbitrary File Upload vulnerability
10
57 minutes ago
TranslatePress
<= 3.3.1
Unauthenticated Account Takeover vulnerability
9.8
1 hour ago
Formidable Charts
<= 2.0.1
Unauthenticated Arbitrary File Read via 'frm_graph' Parameter vulnerability
7.5
1 hour ago
sanitize-html
>= 1.9.0, <= 2.17.6
NPM: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
5.4
9 hours ago
nanoid
< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
11 hours ago
pnpm
>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
11 hours ago
Easy Waveform Player
<= 1.2.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
11 hours ago
pnpm
>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
12 hours ago
@appium/base-driver
<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
12 hours ago
Divi
<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
13 hours ago
SigmaForms Pro – AI Generated Forms
<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
13 hours ago
DevKit Pro
<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
14 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
7.5
14 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
7.5
14 hours ago
mysql2
< 3.22.0
NPM: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
8.2
14 hours ago
Amelia
8.0-9.6.2
WordPress Booking for Appointments and Events Calendar - Amelia (Premium) plugin 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' vulnerability
9.8
14 hours ago
Load more