Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,728
Mitigations
Mitigation rules
17,200
No official patch
13,372
In triage
1,349
Published soon
28
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WPDM – Premium Packages
7.0.0-7.2.0
Unauthenticated PayPal Webhook Signature Verification Bypass vulnerability
5.3
6 minutes ago
Easy Hide Login
< 1.7
Login Page Protection Bypass / Hidden URL Disclosure vulnerability
5.3
6 minutes ago
Newsletters
< 4.18.1
Unauthenticated Subscriber Record Overwrite and PII Disclosure vulnerability
6.5
7 minutes ago
Payment Plugins for PayPal WooCommerce
< 2.0.27
Unauthenticated Payment Hijacking vulnerability
6.5
1 hour ago
eesy_ID2WP – Publish InDesign HTML5
<= 1.0.3
Unauthenticated Path Traversal to Arbitrary File Read vulnerability
7.5
1 hour ago
Visual Composer Website Builder
<= 45.16.0
Unauthenticated Local File Inclusion vulnerability
9.8
1 hour ago
Directorist
3.1.0-8.9.4
Subscriber+ Arbitrary Listing Deletion vulnerability
6.5
1 hour ago
Jet Form Builder Stripe Gateway
< 1.1.0
Unauthenticated Blind SQLi vulnerability
8.6
1 hour ago
EthPress – Web3 Login
<= 2.3.5
Unauthenticated Authentication Bypass vulnerability
8.1
1 hour ago
WP OAuth Server
< 6.4.0
Subscriber+ Cross-User Account Takeover vulnerability
9
1 hour ago
YAHMAN Add-ons
< 0.9.31
Unauthenticated Arbitrary File Upload vulnerability
9
2 hours ago
elysia
< 1.4.29
NPM: elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
7.5
10 hours ago
@fecommunity/reactpress
<= 3.6.0
NPM: ReactPress has SQL injection via dynamic column names in TypeORM query builders
7.5
11 hours ago
Spectra
<= 2.20.0
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
7.5
11 hours ago
Kirki
<= 6.2.0
Unauthenticated Blind Server-Side Request Forgery vulnerability
5.4
11 hours ago
@openc3/vue-common
>= 5.0.6, <= 7.2.1
NPM: OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
7.6
11 hours ago
WP Multilang
<= 2.4.31
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
YOP Poll
<= 7.0.10
Unauthenticated Origin Validation Error to Administrator Account Takeover vulnerability
8.8
12 hours ago
Admin Notices Manager
<= 1.6.0
SQL Injection vulnerability
7.6
13 hours ago
W4 Post List
<= 3.0.6
SQL Injection vulnerability
7.6
13 hours ago
Load more