The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,167
Mitigations16,677
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Betheme<= 28.4
Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode vulnerability
6.5
15 minutes ago
Gutenverse<= 4.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks vulnerability
6.5
17 minutes ago
Mailgun for WordPress<= 2.2.0
Unauthenticated Server-Side Request Forgery (SSRF) vulnerability
7.2
26 minutes ago
kk Star Ratings<= 5.4.10.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
7.5
26 minutes ago
@arikusi/deepseek-mcp-server>= 1.4.2, < 1.8.0
NPM: @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
5.3
45 minutes ago
@arikusi/deepseek-mcp-server>= 1.4.2, < 1.7.0
NPM: @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
8.6
46 minutes ago
consciousness-explorer< 1.1.2
NPM: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
7.1
48 minutes ago
sublinear-time-solver< 1.6.0
NPM: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
7.1
48 minutes ago
whistle< 2.10.3
NPM: Whistle vulnerable to path traversal
8.7
51 minutes ago
mediasoup>= 3.20.0, <= 3.20.5
NPM: mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
5.6
1 hour ago
FundEngine<= 1.8.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
1 hour ago
Advanced Product Fields (Product Addons) for WooCommerce<= 1.6.21
Unauthenticated Improper Input Validation to Price Bypass vulnerability
7.5
1 hour ago
WS Form LITE<= 1.10.80
Unauthenticated PHP Object Injection vulnerability
9.8
1 hour ago
Events Manager<= 7.3.7.4
Authenticated (Administrator+) Local File Inclusion vulnerability
7.5
1 hour ago
ManageWP Worker< 4.9.37
Unauthenticated Authentication Bypass vulnerability
9.8
2 hours ago
FiboSearch< 1.34.1
Unauthenticated Password-Protected Product Information Disclosure vulnerability
7.5
2 hours ago
Limit Login Attempts Reloaded< 3.3.5
Username Denylist Bypass vulnerability
3.7
2 hours ago
All-in-One WP Migration<= 7.109
Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution vulnerability
8.8
2 hours ago
ShopEngine<= 4.9.4
Authenticated (Shop Manager+) Privilege Escalation to WXR Import 'plugin <wp_option>' Nodes vulnerability
7.2
2 hours ago
Metform<= 4.1.8
Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting vulnerability
6.5
2 hours ago