The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total38,484
Mitigations14,079
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
RegistrationMagic<= 6.0.6.9
WordPress RegistrationMagic - Custom Registration Forms, User Registration, Payment, and User Login plugin <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment vulnerability
5.3
2 hours ago
Complianz<= 7.4.3
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
2 hours ago
User Submitted Posts<= 20260113
Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter vulnerability
5.3
2 hours ago
Video Share VOD<= 2.7.11
Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values vulnerability
6.5
2 hours ago
SiteOrigin Widgets Bundle<= 1.70.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
5.4
2 hours ago
Community Events<= 1.5.7
Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter vulnerability
5.9
2 hours ago
WP Event Aggregator<= 1.8.7
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
2 hours ago
Business Directory<= 6.4.20
Missing Authorization to Unauthenticated Arbitrary Listing Modification vulnerability
5.3
2 hours ago
EventPrime<= 4.2.8.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter vulnerability
4.3
2 hours ago
WP-DownloadManager<= 1.69
Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter vulnerability
2.7
2 hours ago
Dam Spam<= 1.0.8
Cross-Site Request Forgery to Arbitrary Pending Comment Deletion vulnerability
4.3
2 hours ago
YayMail – WooCommerce Email Customizer<= 4.3.2
Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint vulnerability
2.7
2 hours ago
Kali Forms<= 2.4.8
Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure vulnerability
4.3
2 hours ago
YayMail – WooCommerce Email Customizer<= 4.3.2
Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation vulnerability
2.7
2 hours ago
YayMail – WooCommerce Email Customizer<= 4.3.2
Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements vulnerability
5.9
2 hours ago
YayMail – WooCommerce Email Customizer<= 4.3.2
Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action vulnerability
7.2
2 hours ago
Private Comment<= 0.0.4
Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting vulnerability
5.9
2 hours ago
InteractiveCalculator for WordPress<= 1.0.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute vulnerability
6.5
2 hours ago
Cart All In One For WooCommerce<= 1.1.21
Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting vulnerability
7.2
3 hours ago
Gutenberg Blocks by Kadence Blocks<= 3.6.1
Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter vulnerability
4.3
3 hours ago