The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,901
Mitigations16,582
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
gettext-converter< 1.3.3
NPM: gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
6.9
3 hours ago
@nocobase/server< 2.1.5
NPM: NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
0
4 hours ago
@whyour/qinglong< 2.20.1
NPM: Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
9.3
4 hours ago
node-opcua<= 2.165.0
NPM: node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
7.5
4 hours ago
node-opcua<= 2.165.0
NPM: node-opcua missing nonce verification in UserNameIdentityToken authentication
7.7
4 hours ago
next-video<= 2.8.0
NPM: next-video: Unauthenticated arbitrary file read via /api/video request handler
6.9
4 hours ago
@nocobase/plugin-backups< 2.1.19
NPM: NocoBase backup restore schema name allows command injection
6.7
4 hours ago
Easy Elementor Addons<= 2.3.7
Cross Site Request Forgery (CSRF) vulnerability
9.6
10 hours ago
New User Approve<= 3.2.8
Broken Access Control vulnerability
5.3
10 hours ago
InfiniteWP Client<= 1.13.9
SQL Injection vulnerability
7.6
10 hours ago
TranslatePress<= 3.2.5
WordPress TranslatePress - Translate Multilingual sites with AI Translation plugin <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
11 hours ago
EWWW Image Optimizer<= 8.7.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content vulnerability
6.5
12 hours ago
WP Statistics<= 14.16.8
Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter vulnerability
7.1
12 hours ago
Atarim<= 5.1.1
Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta vulnerability
8.1
12 hours ago
TrueBooker<= 1.2.6
Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter vulnerability
9.8
12 hours ago
Speed Optimizer<= 7.8.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes vulnerability
6.5
12 hours ago
PPWP<= 1.9.15
Improper Authorization To Authenticated (Contributor+) Master Password Exposure vulnerability
4.3
12 hours ago
Tourmaster< 5.4.9
Unauthenticated Sensitive Data Disclosure via Order Export vulnerability
5.3
12 hours ago
Vitepos< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
12 hours ago
Vitepos< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
12 hours ago