Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,963
Mitigations
Mitigation rules
16,976
No official patch
13,352
In triage
1,216
Published soon
27
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP Express Checkout (Accept PayPal Payments)
< 2.5.0
Unauthenticated Payment Bypass vulnerability
5.3
8 minutes ago
Spam protection, AntiSpam, FireWall by CleanTalk
< 6.87
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
19 minutes ago
SupportCandy
3.2.9-3.5.2
Unauthenticated Ticket Attachment Disclosure vulnerability
5.3
28 minutes ago
Payment Plugins for PayPal WooCommerce
< 2.0.26
Subscriber+ Stored Payment Method Assignment vulnerability
5.9
31 minutes ago
iTracker360
<= 2.2.0
Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field vulnerability
6.1
31 minutes ago
Quentn WP
1.2.13-1.2.14
Unauthenticated SQLi vulnerability
9.3
34 minutes ago
Loops & Logic
< 4.3.0
Unauthenticated User Data and Site Option Disclosure vulnerability
7.5
41 minutes ago
ELEX WooCommerce Request a Quote
< 2.4.1
Unauthenticated SQLi vulnerability
9.3
50 minutes ago
Chat Help
<= 3.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
7.5
56 minutes ago
Business Intelligence Lite
<= 3.2.0
Authenticated (Subscriber+) Missing Authorization to Privilege Escalation vulnerability
8
1 hour ago
Direct Download for WooCommerce
<= 1.19
Unauthenticated Arbitrary File Read vulnerability
7.5
1 hour ago
Bulk Password Reset
<= 1.3.3
Authenticated (Subscriber+) Arbitrary Password Reset vulnerability
8.8
1 hour ago
@openhop/server
<= 0.3.5
NPM: @openhop/server: Path Traversal in Flow ID File Operations
8.3
8 hours ago
functype-mcp-server
<= 1.4.3
NPM: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
7.8
8 hours ago
@yeger/turbo-graph
<= 2.8.8
NPM: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
8.8
8 hours ago
nuxt-ollama
>= 1.2.26, < 1.3.1
NPM: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
7.5
8 hours ago
Aruba HiSpeed Cache
<= 3.0.14
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
11 hours ago
smol-toml
<= 1.7.0
NPM: smol-toml: Denial of Service via malformed TOML documents
8.2
13 hours ago
Easy Google Fonts
<= 2.0.4
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
6.5
16 hours ago
Advanced Contact form 7 DB
<= 2.1.3
Missing Authorization to Authenticated (Custom+) Unauthorized Data Import vulnerability
4.3
16 hours ago
Load more