The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,611
Mitigations17,177
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WP EasyCart<= 5.9.4
SQL Injection vulnerability
8.5
4 minutes ago
Mollie Forms<= 2.11.0
SQL Injection vulnerability
8.5
22 minutes ago
Live Copy Paste for Elementor<= 1.5.10
SQL Injection vulnerability
8.5
23 minutes ago
Fluent Support<= 2.3.2
Broken Access Control vulnerability
5.4
24 minutes ago
Easy Digital Downloads<= 3.7.0
SQL Injection vulnerability
7.6
27 minutes ago
Premium Blocks – Gutenberg Blocks for WordPress<= 2.3.17
Cross Site Scripting (XSS) vulnerability
6.5
31 minutes ago
WSP MCP &#8211; AI Agents Connector<= 2.7.0
WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability
6.5
32 minutes ago
MarketKing<= 2.1.70
Broken Access Control vulnerability
5.3
1 hour ago
The Post Grid<= 7.9.5
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
WPC Product Bundles for WooCommerce<= 8.6.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Rename wp-login.php to anything you want<= 2.0.1
Unauthenticated SQL Injection vulnerability
7.5
2 hours ago
Ninja Forms3.15.3
Unauthenticated PHP Object Injection vulnerability
7.5
3 hours ago
unleash-server< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
13 hours ago
unleash-server< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
13 hours ago
unleash-server< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
13 hours ago
unleash-server< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
13 hours ago
@novu/js<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
13 hours ago
mppx< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
13 hours ago
mppx< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
13 hours ago
@deepstream/server10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
14 hours ago