Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,757
Mitigations
Mitigation rules
16,886
No official patch
13,325
In triage
1,105
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Jetpack
16.1-16.1.2
WordPress Jetpack plugin 3.2 - 16.1.2 - Missing Authorization on WPCOM Media API Attachment Parent vulnerability
4.3
1 hour ago
Jetpack
16.1-16.1.2
Authenticated (Administrator+) PHP Object Injection vulnerability
7.2
1 hour ago
Ninja Forms - Save Progress
<= 3.0.30
WordPress Ninja Forms - Save Progress plugin <= 3.0.30 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Data Deletion via admin-ajax.php with admin_init Hook vulnerability
4.3
2 hours ago
LearnDash LMS
4.25.0-5.1.6
WordPress LearnDash LMS plugin 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint vulnerability
5.4
2 hours ago
FooGallery
<= 3.3.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute vulnerability
6.5
2 hours ago
Pods
<= 3.3.9.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute vulnerability
6.5
2 hours ago
Custom Contact Forms
<= 7.16
Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters vulnerability
4.3
2 hours ago
YT Player
< 2.1.0
Contributor+ SQLi vulnerability
7.6
4 hours ago
EmbedPress
4.6.0-4.6.3
Unauthenticated Google Reviews API Quota Consumption and Database Bloat vulnerability
5.3
4 hours ago
VikWidgetsLoader
< 1.12.0
Contributor+ Stored XSS vulnerability
6.5
4 hours ago
CatFolders Document Gallery & PDF Library
< 2.0.7
Author+ Stored XSS vulnerability
5.9
4 hours ago
Joli Table Of Contents
< 3.0.3
Author+ Stored XSS vulnerability
5.9
4 hours ago
EmbedPress
4.6.0-4.6.3
Contributor+ Google Reviews Modification vulnerability
2.7
4 hours ago
WP Event SOlution
< 4.1.22
Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation vulnerability
4.9
4 hours ago
EmbedPress
4.6.0-4.6.3
Contributor+ Administrator Email Disclosure vulnerability
2.7
4 hours ago
Kirki
6.0.0-6.2.5
Editor+ SQLi vulnerability
6.8
4 hours ago
King Addons for Elementor
< 51.1.77
Contributor+ Stored XSS vulnerability
6.5
4 hours ago
The Events Calendar
< 6.17.3.1
Contributor+ Non-Public Event, Venue and Organizer Content Disclosure vulnerability
2.7
4 hours ago
WP Event SOlution
< 4.1.21
Contributor+ LFI vulnerability
6.6
4 hours ago
Kirki
6.0.0-6.2.5
Authenticated Collaboration Comment Status Modification vulnerability
2.2
4 hours ago
Load more