Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,925
Mitigations
Mitigation rules
17,300
No official patch
13,368
In triage
1,402
Published soon
21
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
ip-address
<= 10.5.0
NPM: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
6.3
38 minutes ago
ip-address
>= 10.2.0, <= 10.5.0
NPM: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
6.9
39 minutes ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
8.6
43 minutes ago
@grpc/grpc-js-xds
< 1.13.1
NPM: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
6.5
1 hour ago
scim-patch
< 0.9.2
NPM: scim-patch: Mutation of Inherited Built-in Method Objects
4.3
7 hours ago
code-ollama
<= 0.36.0
NPM: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
7.8
7 hours ago
WP Review Slider Pro
< 12.7.12
Subscriber+ Stored XSS vulnerability
6.5
7 hours ago
File Manager
7.2.2-8.0.4
Unauthenticated Database Backup Disclosure vulnerability
5.9
8 hours ago
Verge3D
4.1.0-4.13.0
Unauthenticated Payment Bypass vulnerability
5.3
8 hours ago
Best Payments Plugin for WP
4.6.20-4.6.25
Unauthenticated Payment Bypass vulnerability
5.3
8 hours ago
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification
1.3.0-2.3.1
Blocked User Restriction Bypass vulnerability
5.4
8 hours ago
Bookly
< 28.3
Unauthenticated Payment Bypass vulnerability
5.3
8 hours ago
Contact Form by WPForms
1.5.0.1-2.0.2.0
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
8 hours ago
Malcure Malware Scanner
< 19.9.7
Multisite Subsite Admin+ Arbitrary File Write and Deletion vulnerability
7.2
8 hours ago
Verge3D
<= 4.13.0
Unauthenticated Product Download Disclosure vulnerability
5.3
8 hours ago
WPeMatico RSS Feed Fetcher
< 2.8.27
Contributor+ Post Publication and Author Spoofing vulnerability
4.9
8 hours ago
Download Manager
4.0.0-7.5.5
Unauthenticated Stored XSS vulnerability
7.1
8 hours ago
Testimonials Widget
<= 4.0.4
Unauthenticated SSRF vulnerability
5.8
9 hours ago
File Manager Pro
< 2.1.3
DOM-based XSS vulnerability
7.1
9 hours ago
FileOrganizer
< 1.2.1
DOM-based XSS vulnerability
7.1
9 hours ago
Load more