Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,836
Mitigations
Mitigation rules
17,239
No official patch
13,366
In triage
1,349
Published soon
64
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Elementor Website Builder
<= 4.3.1
Cross Site Request Forgery (CSRF) vulnerability
8.8
55 minutes ago
Knit Pay
<= 9.6.1.0
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
9 hours ago
Wawp
<= 4.8.6
Unauthenticated Privilege Escalation vulnerability
9.8
9 hours ago
s2Member
<= 260814
Unauthenticated Remote Code Execution vulnerability
8.8
9 hours ago
Optima Express + MarketBoost IDX Plugin
<= 8.7.5
Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment vulnerability
7.3
9 hours ago
cline
< 3.0.30
NPM: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
8.8
11 hours ago
@rsdoctor/rspack-plugin
<= 1.5.15
NPM: @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
7.5
11 hours ago
@bytebase/dbhub
< 0.22.6
NPM: @bytebase/dbhub's read-only mode does not prevent database writes
7.4
11 hours ago
@bytebase/dbhub
<= 0.22.4
NPM: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
9.3
11 hours ago
xhtml-purifier
<= 0.4.1
NPM: xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
6.1
11 hours ago
@bsv/wallet-toolbox
>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
11 hours ago
@bsv/wallet-toolbox-client
>= 1.1.47, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
11 hours ago
@bsv/wallet-toolbox-mobile
>= 1.3.21, < 2.4.0
NPM: `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
8.7
11 hours ago
cyberchef
< 11.2.0
NPM: CyberChef: Prototype pollution in Series Chart operation
5
11 hours ago
@aws/lsp-codewhisperer
< 0.0.117
NPM: Language Servers for AWS vulnerable to arbitrary file write
7.8
12 hours ago
@aws/lsp-codewhisperer
< 0.0.113
NPM: Language Servers for AWS Vulnerable to Arbitrary Code Execution
8.5
12 hours ago
Asset CleanUp: Page Speed Booster
<= 1.4.0.5
Authenticated (Administrator+) Server-Side Request Forgery vulnerability
5.5
12 hours ago
SSL Zen
<= 4.7.42
Authenticated (Administrator+) Path Traversal to Arbitrary File Read vulnerability
4.9
12 hours ago
Modula Image Gallery
<= 3.0.1
Missing Authorization to Unauthenticated Private Gallery Image Disclosure vulnerability
5.3
12 hours ago
Gutenverse
<= 4.0.8
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
Load more