The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,630
Mitigations14,789
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Responsive Plus< 3.4.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
44 minutes ago
WP Job Portal<= 2.4.9
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
8.8
49 minutes ago
ThemeREX Addons< 2.38.5
Unauthenticated Arbitrary File Upload vulnerability
10
50 minutes ago
Download Monitor<= 5.1.7
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
5.3
1 hour ago
Twentig Supercharged Block Editor<= 1.9.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability
6.5
1 hour ago
WP Lightbox 2< 3.0.7
Admin+ Stored XSS vulnerability
5.9
1 hour ago
Conditional Menus<= 1.2.6
Cross-Site Request Forgery to Menu Options Update vulnerability
4.3
1 hour ago
Complianz<= 7.4.4.2
WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
6.5
1 hour ago
Elementor Website Builder<= 3.35.7
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
4.3
1 hour ago
Ads by WPQuads<= 2.0.98.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Ad Metadata Parameters vulnerability
6.5
2 days ago
PageLayer<= 2.0.7
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
5.3
2 days ago
Ninja Forms<= 3.14.1
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
6.5
2 days ago
Amelia<= 9.1.2
Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability
8.8
2 days ago
DSGVO snippet for Leaflet Map and its Extensions<= 3.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability
6.5
2 days ago
FormLift for Infusionsoft Web Forms<= 7.5.21
Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow vulnerability
5.3
2 days ago
Blog2Social<= 8.8.2
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability
4.3
2 days ago
Simple Download Counter<= 2.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute vulnerability
6.5
2 days ago
BWL Advanced FAQ Manager Lite<= 1.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id' Shortcode Attribute vulnerability
6.5
2 days ago
ShortPixel Image Optimizer<= 6.4.3
Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability
5.9
2 days ago
PeproDev Ultimate Invoice< 2.2.6
Unauthenticated Invoice Archive Download vulnerability
5.3
2 days ago