Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,967
Mitigations
Mitigation rules
16,613
No official patch
13,333
In triage
1,077
Published soon
3
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Templately
< 3.7.1
Unauthenticated Administrator Templately Cloud Connection Overwrite vulnerability
6.5
1 hour ago
Kirki
< 6.2.1
Unauthenticated Arbitrary Shortcode Execution via Form Email Actions vulnerability
6.5
1 hour ago
TeraWallet – For WooCommerce
< 1.6.10
WordPress TeraWallet - Wallet for WooCommerce plugin < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up vulnerability
4.3
2 hours ago
EONSR AEO Agent
<= 3.7.9
Unauthenticated Stored XSS via Scheduled Post Creation vulnerability
7.1
2 hours ago
Infility Global
<= 2.15.34
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Chat On Desk Order Notifications
< 1.0.9
Unauthenticated Account Takeover vulnerability
8.1
2 hours ago
SMS Alert Order Notifications
< 3.9.8
Unauthenticated Account Takeover vulnerability
9.8
2 hours ago
jsonata
< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
jsonata
< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
jsonata
<= 1.8.7
NPM: JSONata: Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
@keystone-6/core
<= 6.5.2
NPM: Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
7.5
2 days ago
defuddle
<= 0.19.0
NPM: Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
8.2
2 days ago
unleash-server
< 8.0.3
NPM: Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
4.1
2 days ago
unleash-server
< 7.5.2
NPM: Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
5.5
2 days ago
unleash-server
< 7.5.2
NPM: Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
7.5
2 days ago
Wawp
<= 4.8.6
Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure vulnerability
9.8
2 days ago
WPForms Pro
<= 2.0.0.2
Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values vulnerability
7.1
2 days ago
JSON Options
<= 0.0.4
Unauthenticated Arbitrary Options Update vulnerability
9.8
2 days ago
Depicter Slider
< 4.8.0
Editor+ Arbitrary File Upload via ZIP Import vulnerability
9.1
2 days ago
Kirki
< 6.2.3
Editor+ Stored XSS via Font Zip Upload vulnerability
6.5
2 days ago
Load more