The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,309
Mitigations14,600
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Contextual Related Posts< 4.2.2
Broken Access Control vulnerability
5.3
1 hour ago
Writeprint Stylometry<= 0.1
Reflected Cross-Site Scripting via 'p' Parameter vulnerability
7.1
3 hours ago
[CR]Paid Link Manager<= 0.5
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
WP Go Maps<= 10.0.05
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
6.5
4 hours ago
Duplicate Post<= 4.5
Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability
5.4
8 hours ago
Subscriptions for WooCommerce<= 1.9.2
Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability
5.3
8 hours ago
Royal Elementor Addons<= 1.7.1049
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
5.3
8 hours ago
Booster for WooCommerce< 7.11.3
Broken Access Control vulnerability
5.3
1 day ago
WowStore<= 4.4.3
WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
9.3
1 day ago
NEX-Forms<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id vulnerability
7.5
1 day ago
NEX-Forms<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license vulnerability
4.3
1 day ago
WP User Frontend<= 4.2.8
Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability
5.3
1 day ago
Wicked Folders<= 4.1.0
Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion vulnerability
4.3
1 day ago
Thim Elementor Kit<= 1.3.7
Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
5.3
1 day ago
WP EasyPay<= 4.2.11
Broken Access Control vulnerability
5.4
1 day ago
Modern Events Calendar<= 7.29.0
Broken Access Control vulnerability
5.3
1 day ago
Total Poll Lite<= 4.12.0
Remote Code Execution (RCE) vulnerability
9.9
2 days ago
WooCommerce Infinite Scroll<= 1.6.2
PHP Object Injection vulnerability
8.8
2 days ago
StoreCustomizer<= 2.6.3
Broken Access Control vulnerability
6.5
2 days ago
Dokan<= 4.2.4
Broken Authentication vulnerability
8.8
2 days ago