Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,846
Mitigations
Mitigation rules
16,938
No official patch
13,331
In triage
1,200
Published soon
27
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@xmldom/xmldom
>= 0.9.0-beta.9, <= 0.9.10
NPM: xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
8.7
35 minutes ago
@xmldom/xmldom
>= 0.7.0, <= 0.8.13
NPM: xmldom: Element name injection via createElement() bypasses requireWellFormed
8.7
36 minutes ago
xmldom
<= 0.6.0
NPM: xmldom: Element name injection via createElement() bypasses requireWellFormed
8.7
36 minutes ago
@xmldom/xmldom
>= 0.7.0, <= 0.8.13
NPM: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
8.7
36 minutes ago
xmldom
<= 0.6.0
NPM: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
8.7
36 minutes ago
liquidjs
<= 10.27.1
NPM: LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
7.5
2 hours ago
csv-parse
< 7.0.2
NPM: node-csv: Prototype replacement still reachable via columns path
6.9
3 hours ago
@swc/html
< 1.15.47-nightly-20260729.1
NPM: SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
3 hours ago
ilGhera Reviso Exporter for WooCommerce
<= 1.2.3
Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function vulnerability
4.3
3 hours ago
WPFunnels
<= 3.12.13
Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation vulnerability
5.3
3 hours ago
Awesome Support
<= 6.3.9
Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial vulnerability
4.3
3 hours ago
WP Recipe Maker
<= 10.8.0
Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing vulnerability
4.3
4 hours ago
WP Event SOlution
<= 4.1.17
Missing Authorization to Authenticated (Subscriber+) Notification Flow Management vulnerability
5.4
4 hours ago
WP Crowdfunding
<= 2.2.1
Authenticated (Shop Manager+) SQL Injection vulnerability
4.9
6 hours ago
Podlove Podcast Publisher
<= 4.5.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
6 hours ago
Mail Mint
<= 1.31.0
Authenticated (Custom+) SQL Injection vulnerability
8.5
6 hours ago
Ninja Forms
<= 3.14.6
Authenticated (Administrator+) PHP Object Injection vulnerability
7.2
6 hours ago
My Calendar
<= 3.8.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
6 hours ago
My Calendar
<= 3.8.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
6 hours ago
WP Event SOlution
<= 4.1.22
Authenticated (Custom+) Local File Inclusion vulnerability
7.5
7 hours ago
Load more