The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,158
Mitigations17,388
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Redux Framework<= 4.5.14
Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion vulnerability
4.3
54 minutes ago
Advanced Woo Labels<= 2.51
Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
59 minutes ago
AI Engine<= 3.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Extendify<= 3.1.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
ClearSale Total<= 3.4.2
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
Simply Schedule Appointments<= 1.6.12.32
Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion vulnerability
7.5
1 hour ago
Zella Theme< 2.6.3
Unauthenticated Arbitrary File Upload vulnerability
10
1 hour ago
WP User Frontend3.5.29-4.3.11
Unauthenticated Privilege Escalation vulnerability
7.4
1 hour ago
ByteCoreStack &#8211; MCP Connector for AI Tools<= 1.2.3
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
1 hour ago
Super Forms<= 6.3.316
Unauthenticated Privilege Escalation vulnerability
9.8
1 hour ago
Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform<= 2.15.0
Unauthenticated Authentication Bypass vulnerability
9.8
1 hour ago
WPC Shop as a Customer for WooCommerce<= 2.0.0
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Super Forms<= 6.3.316
Authenticated (Subscriber+) Arbitrary File/Directory Deletion vulnerability
8.6
2 hours ago
fastify< 5.12.5
NPM: fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
5.9
8 hours ago
hono< 4.13.7
NPM: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
4.7
9 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to request body replacement via an async validation result collision
8.1
9 hours ago
fastify>= 4.0.0, < 5.12.2
NPM: fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
7.5
9 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to request validation bypass via skipped boolean false schemas
7.5
9 hours ago
fastify< 5.12.2
NPM: fastify vulnerable to header validation bypass via incomplete schema case normalization
7.5
9 hours ago
@astrojs/netlify>= 5.2.0, <= 8.2.3
NPM: Astro: Netlify Image CDN allowlist bypass enables SSRF
6.3
9 hours ago