Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,477
Mitigations
Mitigation rules
16,832
No official patch
13,329
In triage
1,127
Published soon
17
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
nanoid
< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
30 minutes ago
pnpm
>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
31 minutes ago
pnpm
>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
54 minutes ago
@appium/base-driver
<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
59 minutes ago
Divi
<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
2 hours ago
SigmaForms Pro – AI Generated Forms
<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
2 hours ago
DevKit Pro
<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
2 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
7.5
3 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
7.5
3 hours ago
mysql2
< 3.22.0
NPM: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
8.2
3 hours ago
Amelia
8.0-9.6.2
WordPress Booking for Appointments and Events Calendar - Amelia (Premium) plugin 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' vulnerability
9.8
3 hours ago
Divi
<= 4.27.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode vulnerability
6.5
5 hours ago
WP File Download
<= 6.3.4
Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter vulnerability
7.7
5 hours ago
Gravity Forms
<= 3.0.2
Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion vulnerability
9
12 hours ago
WPBakery Page Builder
<= 8.7.4
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter vulnerability
6.5
12 hours ago
Welcart e-Commerce
<= 2.12.1
Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter vulnerability
7.1
12 hours ago
Nokri
<= 1.6.6
WordPress Nokri - Job Board WordPress Theme plugin <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter vulnerability
9.8
12 hours ago
Simple Membership
<= 4.8.1
Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding vulnerability
9.8
12 hours ago
FS Poster
<= 8.0.1
Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting vulnerability
8.8
12 hours ago
WP Recipe Maker Premium
<= 10.5.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'wprm-call-to-action' Shortcode vulnerability
6.5
13 hours ago
Load more