Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,170
Mitigations
Mitigation rules
16,179
No official patch
13,202
In triage
1,105
Published soon
31
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
User Access Manager
<= 2.3.12
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
6 minutes ago
Authora : Easy login with mobile number
< 1.7.7
WordPress Authora : Easy login with mobile number plugin < 1.7.7 - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover vulnerability
9.8
8 minutes ago
Webinfos
<= 1.2
Unauthenticated Arbitrary File Upload vulnerability
10
11 minutes ago
Login Social
<= 1.0.4
Unauthenticated Account Takeover vulnerability
9.8
13 minutes ago
POUCO Import Users
<= 1.0.0
Unauthenticated Privilege Escalation vulnerability
9.8
17 minutes ago
Lenxel WP
<= 1.0.31
Unauthenticated Account Takeover vulnerability
9.8
20 minutes ago
Support Genix
< 1.4.48
Unauthenticated Arbitrary File Read vulnerability
7.5
22 minutes ago
Bit File Manager
6.0-6.9
WordPress File Manager plugin 6.0-6.9 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion vulnerability
8.6
25 minutes ago
WPMU DEV Dashboard
<= 5.0.0
Authentication Bypass to Arbitrary plugin Installation (Remote Code Execution) vulnerability
8.1
27 minutes ago
Restrict Content
<= 4.0.0
Unauthenticated Password Reset Link Poisoning to Account Takeover vulnerability
9.8
1 hour ago
FluentSMTP
<= 2.2.95
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Popup by Supsystic
<= 1.12.0
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
1 hour ago
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
7.5
9 hours ago
nuxt
>= 3.4.0, < 3.21.10
NPM: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
8.1
10 hours ago
@nuxt/devtools
< 3.3.1
NPM: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
9.6
10 hours ago
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthorized Component Instantiation via Server Island Props
4.8
10 hours ago
nuxt
>= 4.4.0, <= 4.5.0
NPM: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
7.5
10 hours ago
nuxt
>= 3.21.7, < 3.21.10
NPM: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
8.2
10 hours ago
nuxt
>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
7.5
10 hours ago
electron
< 39.8.8
NPM: Electron: Sandboxed iframes can launch external protocol handlers
5.4
13 hours ago
Load more