Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,475
Mitigations
Mitigation rules
16,359
No official patch
13,257
In triage
1,138
Published soon
49
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Epeken All Kurir
<= 2.1.2
Unauthenticated Order Payment Confirmation Forgery vulnerability
3.7
5 hours ago
Paymob for WooCommerce
< 4.1.9
Unauthenticated SQL Injection via Paymob Callback Pixel Lookup vulnerability
9.3
5 hours ago
WishList Member X
<= 3.34.1
Unauthenticated Account Takeover via 'mergewith' Parameter vulnerability
9.8
5 hours ago
Embed Google Photos album
<= 2.2.1
Contributor+ Stored XSS via link Shortcode Attribute vulnerability
6.5
5 hours ago
Bit Form
<= 3.2.0
Authenticated (Administrator+) SQL Injection via 'filterText' Parameter vulnerability
7.6
5 hours ago
affiliate-toolkit
<= 3.8.8
Authenticated (Administrator+) SQL Injection via 'orderby' Parameter vulnerability
7.6
5 hours ago
Astro Booking Engine
<= 1.4.0
Cross-Site Request Forgery to Settings Reset vulnerability
5.4
5 hours ago
W3 Total Cache
<= 2.10.3
Unauthenticated Stored Cross-Site Scripting via Comment Author Name vulnerability
7.1
5 hours ago
KiviCare
< 4.5.2
Unauthenticated Privilege Escalation via Registration vulnerability
9.8
6 hours ago
Ecwid Shopping Cart
< 7.0.9
Subscriber+ Store Disconnection via 'ec_disconnect' Action vulnerability
5.4
6 hours ago
Email Verification for WooCommerce
< 3.2.6
Unauthenticated Account Takeover via Type-Juggling Authentication Bypass vulnerability
9.8
6 hours ago
ShopEngine
< 4.9.3
Customer PII Disclosure via Forced Authentication vulnerability
5.4
6 hours ago
Amelia
< 2.4.6
Provider+ Cross-Customer Appointment Data Disclosure via IDOR vulnerability
4.3
6 hours ago
WP Helper Premium
< 4.7.6
Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation vulnerability
5.3
6 hours ago
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
< 6.0.2
Unauthenticated Reservation Status Modification vulnerability
5.3
6 hours ago
PPWP
<= 1.9.21
WordPress PPWP - Password Protect Pages plugin <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
6 hours ago
FluentForm
<= 6.2.11
Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values vulnerability
7.1
6 hours ago
Prevent Direct Access
<= 2.8.8.8
WordPress Prevent Direct Access - Protect WordPress Files plugin <= 2.8.8.8 - Unauthenticated Protected File Access vulnerability
5.3
6 hours ago
Quick Paypal Payments
<= 5.7.50
Unauthenticated Payment Bypass via PayPal IPN vulnerability
5.3
7 hours ago
Payment Button for PayPal
<= 1.2.3.44
Unauthenticated Payment Price Manipulation vulnerability
5.3
7 hours ago
Load more