Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
39,630
Mitigations
Mitigation rules
14,789
No official patch
11,271
In triage
1,502
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
Responsive Plus
< 3.4.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
44 minutes ago
WP Job Portal
<= 2.4.9
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
8.8
49 minutes ago
ThemeREX Addons
< 2.38.5
Unauthenticated Arbitrary File Upload vulnerability
10
50 minutes ago
Download Monitor
<= 5.1.7
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
5.3
1 hour ago
Twentig Supercharged Block Editor
<= 1.9.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability
6.5
1 hour ago
WP Lightbox 2
< 3.0.7
Admin+ Stored XSS vulnerability
5.9
1 hour ago
Conditional Menus
<= 1.2.6
Cross-Site Request Forgery to Menu Options Update vulnerability
4.3
1 hour ago
Complianz
<= 7.4.4.2
WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
6.5
1 hour ago
Elementor Website Builder
<= 3.35.7
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
4.3
1 hour ago
Ads by WPQuads
<= 2.0.98.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Ad Metadata Parameters vulnerability
6.5
2 days ago
PageLayer
<= 2.0.7
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
5.3
2 days ago
Ninja Forms
<= 3.14.1
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
6.5
2 days ago
Amelia
<= 9.1.2
Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability
8.8
2 days ago
DSGVO snippet for Leaflet Map and its Extensions
<= 3.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability
6.5
2 days ago
FormLift for Infusionsoft Web Forms
<= 7.5.21
Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow vulnerability
5.3
2 days ago
Blog2Social
<= 8.8.2
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability
4.3
2 days ago
Simple Download Counter
<= 2.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute vulnerability
6.5
2 days ago
BWL Advanced FAQ Manager Lite
<= 1.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id' Shortcode Attribute vulnerability
6.5
2 days ago
ShortPixel Image Optimizer
<= 6.4.3
Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability
5.9
2 days ago
PeproDev Ultimate Invoice
< 2.2.6
Unauthenticated Invoice Archive Download vulnerability
5.3
2 days ago
Load more