Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,080
Mitigations
Mitigation rules
16,167
No official patch
13,193
In triage
1,100
Published soon
26
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
electron
>= 40.0.0-alpha.1, < 40.10.6
NPM: Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
5.9
10 minutes ago
electron
< 39.8.8
NPM: Electron: HTTP redirect followed into local file loader
5.9
13 minutes ago
electron
< 39.8.10
NPM: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
7.4
18 minutes ago
electron
< 39.8.8
NPM: Electron: Extension tab APIs operate across session boundaries
6.6
20 minutes ago
electron
< 39.8.6
NPM: Electron: shell.openPath path validation bypass via embedded null byte
6
20 minutes ago
electron
< 39.8.9
NPM: Electron: Context isolation bypass via Function.prototype.bind hijack
7.5
31 minutes ago
electron
< 39.8.8
NPM: Electron: Cross-origin iframe can position native autofill popup
3.1
37 minutes ago
electron
< 39.8.7
NPM: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
5.9
41 minutes ago
electron
< 39.8.10
NPM: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
3.9
50 minutes ago
electron
< 39.8.8
NPM: Electron: Parent process code-sign check is spoofable
6.3
56 minutes ago
ghost
>= 5.46.1, < 6.21.2
NPM: Ghost Content API filter bypass reveals private fields
5.3
1 hour ago
ghost
>= 4.9.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Feature Image Captions
4.3
1 hour ago
ghost
>= 6.26.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery Mitigation Issue
4
1 hour ago
Instagram Feed
<= 6.11.3
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
Dokan
<=5.0.2-<=5.0.2
Missing Authorization to Authenticated (Vendor+) Privilege Escalation vulnerability
8.8
3 hours ago
Points and Rewards for WooCommerce
< 2.10.1
Unauthenticated Arbitrary User Wallet & Points Manipulation vulnerability
5.9
3 hours ago
VikRentItems Flexible Rental Management System
<= 1.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Advanced Views
<= 3.9.1
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
6.5
3 hours ago
Udimi Tools
<= 3.2
Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset vulnerability
6.5
3 hours ago
Layouts for WPBakery
<= 1.1.3
Missing Authorization to Unauthenticated Template Cache Manipulation vulnerability
6.5
3 hours ago
Load more