Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,024
Mitigations
Mitigation rules
16,640
No official patch
13,331
In triage
1,051
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
AllCoach
< 1.0.2
Unauthenticated Account Takeover vulnerability
9.8
2 hours ago
Filter & Grids
< 3.11.3
Unauthenticated Private/Draft Post Disclosure vulnerability
5.3
2 hours ago
BookingPress
< 1.5.6
Unauthenticated PHP Object Injection vulnerability
9.8
3 hours ago
ProfilePress
< 4.16.17
Subscriber+ Subscription Cancellation via IDOR vulnerability
4.3
3 hours ago
WP Support Plus Responsive Ticket System
<= 9.1.2
Unauthenticated SQL Injection via filter[elements] Array Keys vulnerability
9.3
3 hours ago
Everest Forms
< 3.5.0
Unauthenticated Missing Authorization via Site Assistant REST Endpoints vulnerability
5.3
3 hours ago
SALESmanago & Leadoo
< 3.11.3
Subscriber+ SQL Injection vulnerability
8.5
3 hours ago
Royal MCP
< 1.4.26
Subscriber+ Insufficient Authorization in MCP Tools vulnerability
8.1
3 hours ago
Notifier
< 2.6
Subscriber+ LFI vulnerability
8.8
3 hours ago
Printcart Web to Print Product Designer for WooCommerce
<= 2.8.6
Path Traversal vulnerability
5.3
3 hours ago
Passster
< 4.3.9
Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass vulnerability
5.3
3 hours ago
Charitable
< 1.8.12
Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass vulnerability
5.3
3 hours ago
LitExtension: WooCommerce Migration Plugin
<= 1.2.6
Connector Token Takeover via CSRF vulnerability
4.3
3 hours ago
myCred
< 3.2.5
Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED vulnerability
5.3
3 hours ago
WP Event SOlution
< 4.1.21
Contributor+ Server-Side Request Forgery vulnerability
4.9
4 hours ago
AI Engine
<= 3.6.0
WordPress AI Engine plugin 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools vulnerability
7.2
4 hours ago
Drag and Drop Multiple File Upload – Contact Form 7
< 1.3.9.9
Unauthenticated RCE via Control Character Filename Bypass vulnerability
8.1
4 hours ago
Duplicate Post
< 1.5.6
Authenticated Arbitrary Post Content and Password Disclosure vulnerability
4.3
4 hours ago
Duplicate Post
< 1.5.6
Author+ Password-Protected Post Content Disclosure vulnerability
2.7
4 hours ago
Media LIbrary Assistant
< 3.40
Author+ SQL Injection via mla_search_connector vulnerability
8.5
4 hours ago
Load more