Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
38,970
Mitigations
Mitigation rules
14,473
No official patch
11,188
In triage
1,507
Published soon
27
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
WP All Import
<= 4.0.0
Reflected Cross-Site Scripting via 'filepath' vulnerability
7.1
8 hours ago
WowOptin
<= 1.4.24
WordPress WowOptin: Next-Gen Popup Maker - Create Stunning Popups and Optins for Lead Generation plugin <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Installation vulnerability
8.8
8 hours ago
Drag and Drop Multiple File Upload – Contact Form 7
<= 1.3.9.5
Unauthenticated Arbitrary File Upload vulnerability
10
9 hours ago
Contact Form Entries
<= 1.4.7
Unauthenticated PHP Object Injection via 'download_csv' vulnerability
9.8
9 hours ago
Greenshift
<= 12.8.3
WordPress Greenshift - animation and page builder blocks plugin <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup vulnerability
5.3
18 hours ago
Greenshift
<= 12.8.5
WordPress Greenshift - animation and page builder blocks plugin <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
18 hours ago
LatePoint
<= 5.2.7
Authenticated (Agent+) Privilege Escalation vulnerability
8.8
1 day ago
Fluent Forms Pro Add On Pack
<= 6.1.17
Unauthenticated Stored Cross-Site Scripting via Draft Form Submission vulnerability
7.1
1 day ago
WPBookit
<= 1.0.8
Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters vulnerability
7.1
1 day ago
Fluent Forms Pro Add On Pack
<= 6.1.17
Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability
7.5
1 day ago
Mail Mint
< 1.19.5
Unauthenticated Emails Disclosure vulnerability
7.5
1 day ago
Restrict Content
<= 3.2.20
WordPress Membership plugin - Restrict Content plugin <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level' vulnerability
8.1
1 day ago
Page and Post Clone
<= 6.3
Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter vulnerability
8.5
1 day ago
Media LIbrary Assistant
<= 3.33
Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification vulnerability
4.3
1 day ago
Apocalypse Meow
<= 22.1.0
Authenticated (Administrator+) SQL Injection via 'type' Parameter vulnerability
7.6
1 day ago
OoohBoi Steroids for Elementor
<= 2.1.24
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls vulnerability
6.5
1 day ago
My Calendar
<= 3.7.3
WordPress My Calendar - Accessible Event Manager plugin <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
1 day ago
Seraphinite Accelerator
<= 2.28.14
Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
4.3
1 day ago
Seraphinite Accelerator
<= 2.28.14
Missing Authorization to Authenticated (Subscriber+) Log Clearing vulnerability
4.3
1 day ago
ionCube tester plus
<= 1.3
Arbitrary File Download vulnerability
7.5
2 days ago
Load more