The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,459
Mitigations16,343
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Epeken All Kurir<= 2.1.2
Unauthenticated Order Payment Confirmation Forgery vulnerability
3.7
15 minutes ago
Paymob for WooCommerce< 4.1.9
Unauthenticated SQL Injection via Paymob Callback Pixel Lookup vulnerability
9.3
16 minutes ago
WishList Member X<= 3.34.1
Unauthenticated Account Takeover via 'mergewith' Parameter vulnerability
9.8
23 minutes ago
Embed Google Photos album<= 2.2.1
Contributor+ Stored XSS via link Shortcode Attribute vulnerability
6.5
24 minutes ago
Bit Form<= 3.2.0
Authenticated (Administrator+) SQL Injection via 'filterText' Parameter vulnerability
7.6
32 minutes ago
affiliate-toolkit<= 3.8.8
Authenticated (Administrator+) SQL Injection via 'orderby' Parameter vulnerability
7.6
33 minutes ago
Astro Booking Engine<= 1.4.0
Cross-Site Request Forgery to Settings Reset vulnerability
5.4
34 minutes ago
W3 Total Cache<= 2.10.3
Unauthenticated Stored Cross-Site Scripting via Comment Author Name vulnerability
7.1
35 minutes ago
KiviCare< 4.5.2
Unauthenticated Privilege Escalation via Registration vulnerability
9.8
1 hour ago
Ecwid Shopping Cart< 7.0.9
Subscriber+ Store Disconnection via 'ec_disconnect' Action vulnerability
5.4
1 hour ago
Email Verification for WooCommerce< 3.2.6
Unauthenticated Account Takeover via Type-Juggling Authentication Bypass vulnerability
9.8
1 hour ago
ShopEngine< 4.9.3
Customer PII Disclosure via Forced Authentication vulnerability
5.4
1 hour ago
Amelia< 2.4.6
Provider+ Cross-Customer Appointment Data Disclosure via IDOR vulnerability
4.3
1 hour ago
WP Helper Premium< 4.7.6
Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation vulnerability
5.3
1 hour ago
Food Menu – Restaurant Menu & Online Ordering for WooCommerce< 6.0.2
Unauthenticated Reservation Status Modification vulnerability
5.3
1 hour ago
PPWP<= 1.9.21
WordPress PPWP - Password Protect Pages plugin <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
1 hour ago
FluentForm<= 6.2.11
Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values vulnerability
7.1
1 hour ago
Prevent Direct Access<= 2.8.8.8
WordPress Prevent Direct Access - Protect WordPress Files plugin <= 2.8.8.8 - Unauthenticated Protected File Access vulnerability
5.3
1 hour ago
Quick Paypal Payments<= 5.7.50
Unauthenticated Payment Bypass via PayPal IPN vulnerability
5.3
1 hour ago
Payment Button for PayPal<= 1.2.3.44
Unauthenticated Payment Price Manipulation vulnerability
5.3
1 hour ago