Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,089
Mitigations
Mitigation rules
17,016
No official patch
13,354
In triage
1,233
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
yayson
<= 4.2.0
NPM: yayson: Prototype pollution in Store/LegacyStore deserialization
9.1
32 minutes ago
@mockoon/commons-server
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
39 minutes ago
@mockoon/cli
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
39 minutes ago
@mockoon/commons-server
<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
39 minutes ago
@mockoon/cli
<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
39 minutes ago
mcp-from-openapi
>= 2.3.0, < 2.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
41 minutes ago
@frontmcp/adapters
>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
41 minutes ago
frontmcp
>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
41 minutes ago
The Events Calendar
<= 6.17.4
Unauthenticated PHP Object Injection to Remote Code Execution vulnerability
9.8
3 hours ago
The Events Calendar
<= 6.17.3
Unauthenticated Code Injection to Remote Code Execution vulnerability
9.8
3 hours ago
GEO my WordPress
<= 4.5.5.3
Unauthenticated Local File Inclusion vulnerability
7.5
3 hours ago
MPG
<= 4.2.1
Unauthenticated SQL Injection vulnerability
9.3
3 hours ago
Tutor LMS
<= 4.0.7
Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution vulnerability
8.8
3 hours ago
bbPress
<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
3 hours ago
DT LMS – elearning, WordPress LMS Plugin
<= 1.1
Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification vulnerability
5.3
3 hours ago
ElasticPress
<= 5.3.4
Sensitive Data Exposure vulnerability
5.3
4 hours ago
Master Addons for Elementor
<= 3.2.2
Broken Access Control vulnerability
7.1
4 hours ago
WP-Members
<= 3.5.6
Reflected Cross-Site Scripting vulnerability
7.1
8 hours ago
Registration Form for WooCommerce
1.1.0-1.1.2
Contributor+ Privilege Escalation vulnerability
8.8
8 hours ago
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons
< 3.3.3
Unauthenticated Stored XSS vulnerability
7.1
8 hours ago
Load more