Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,611
Mitigations
Mitigation rules
17,177
No official patch
13,371
In triage
1,404
Published soon
4
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP EasyCart
<= 5.9.4
SQL Injection vulnerability
8.5
4 minutes ago
Mollie Forms
<= 2.11.0
SQL Injection vulnerability
8.5
22 minutes ago
Live Copy Paste for Elementor
<= 1.5.10
SQL Injection vulnerability
8.5
23 minutes ago
Fluent Support
<= 2.3.2
Broken Access Control vulnerability
5.4
24 minutes ago
Easy Digital Downloads
<= 3.7.0
SQL Injection vulnerability
7.6
27 minutes ago
Premium Blocks – Gutenberg Blocks for WordPress
<= 2.3.17
Cross Site Scripting (XSS) vulnerability
6.5
31 minutes ago
WSP MCP – AI Agents Connector
<= 2.7.0
WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability
6.5
32 minutes ago
MarketKing
<= 2.1.70
Broken Access Control vulnerability
5.3
1 hour ago
The Post Grid
<= 7.9.5
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
WPC Product Bundles for WooCommerce
<= 8.6.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Rename wp-login.php to anything you want
<= 2.0.1
Unauthenticated SQL Injection vulnerability
7.5
2 hours ago
Ninja Forms
3.15.3
Unauthenticated PHP Object Injection vulnerability
7.5
3 hours ago
unleash-server
< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
13 hours ago
unleash-server
< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
13 hours ago
unleash-server
< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
13 hours ago
unleash-server
< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
13 hours ago
@novu/js
<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
13 hours ago
mppx
< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
13 hours ago
mppx
< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
13 hours ago
@deepstream/server
10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
14 hours ago
Load more