Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,582
Mitigations
Mitigation rules
17,172
No official patch
13,370
In triage
1,420
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP User Manager
<= 2.9.19
Broken Access Control vulnerability
5.3
54 minutes ago
9router
<= 0.5.4
NPM: 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
5.3
1 hour ago
9router
<= 0.5.4
NPM: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
7.3
1 hour ago
TrustedLogin Connector
<= 2.0.3
Sensitive Data Exposure vulnerability
5.3
1 hour ago
@aborruso/ckan-mcp-server
<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
2 hours ago
@sync-in/server
<= 2.4.0
NPM: Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
5.3
2 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
6.5
2 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
8.1
2 hours ago
@sync-in/server
<= 2.3.0
NPM: @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
6.8
2 hours ago
@roomi-fields/notebooklm-mcp
>= 1.6.0, < 2.0.3
NPM: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
7.1
2 hours ago
WordPress
<= 7.1.1
Unauthenticated Local File Inclusion to Remote Code Execution vulnerability
9.2
3 hours ago
Ninja Forms
<= 3.15.3
Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
WP Yelp Review Slider
<= 9.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
CTX Feed
<= 6.6.43
Authenticated (Shop Manager+) Path Traversal to File Deletion vulnerability
4.9
4 hours ago
TranslatePress
<= 3.3.5
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
Booking Calendar
<= 11.8.3
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
GiveWP
< 4.16.9
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
5 hours ago
Payment Gateway for PayPal on WooCommerce
< 9.2.1
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
Meow Gallery
< 5.5.5
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
5 hours ago
Forminator
< 1.57.2.1
Authenticated Privilege Escalation vulnerability
6.6
5 hours ago
Load more