Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,893
Mitigations
Mitigation rules
16,582
No official patch
13,324
In triage
1,070
Published soon
95
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@nocobase/server
< 2.1.5
NPM: NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
0
8 minutes ago
@whyour/qinglong
< 2.20.1
NPM: Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
9.3
13 minutes ago
node-opcua
<= 2.165.0
NPM: node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
7.5
14 minutes ago
node-opcua
<= 2.165.0
NPM: node-opcua missing nonce verification in UserNameIdentityToken authentication
7.7
15 minutes ago
next-video
<= 2.8.0
NPM: next-video: Unauthenticated arbitrary file read via /api/video request handler
6.9
15 minutes ago
@nocobase/plugin-backups
< 2.1.19
NPM: NocoBase backup restore schema name allows command injection
6.7
20 minutes ago
Easy Elementor Addons
<= 2.3.7
Cross Site Request Forgery (CSRF) vulnerability
9.6
6 hours ago
New User Approve
<= 3.2.8
Broken Access Control vulnerability
5.3
6 hours ago
InfiniteWP Client
<= 1.13.9
SQL Injection vulnerability
7.6
6 hours ago
TranslatePress
<= 3.2.5
WordPress TranslatePress - Translate Multilingual sites with AI Translation plugin <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
7 hours ago
EWWW Image Optimizer
<= 8.7.3
Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content vulnerability
6.5
7 hours ago
WP Statistics
<= 14.16.8
Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter vulnerability
7.1
7 hours ago
Atarim
<= 5.1.1
Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta vulnerability
8.1
7 hours ago
TrueBooker
<= 1.2.6
Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter vulnerability
9.8
7 hours ago
Speed Optimizer
<= 7.8.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes vulnerability
6.5
7 hours ago
PPWP
<= 1.9.15
Improper Authorization To Authenticated (Contributor+) Master Password Exposure vulnerability
4.3
7 hours ago
Tourmaster
< 5.4.9
Unauthenticated Sensitive Data Disclosure via Order Export vulnerability
5.3
8 hours ago
Vitepos
< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
8 hours ago
Vitepos
< 3.6.0
Outlet Manager+ Privilege Escalation vulnerability
7.2
8 hours ago
Amelia
< 9.7
Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR vulnerability
3.8
8 hours ago
Load more