The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,342
Mitigations17,070
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
CheckView Automated Testing< 2.3.2
Administrator Account Creation via REST API Authentication Bypass vulnerability
9.8
39 minutes ago
Custom Fields< 1.5.1
Unauthenticated Arbitrary File Deletion via Path Traversal vulnerability
8.6
39 minutes ago
Single Sign On For TNG< 2.2.0
Unauthenticated Arbitrary Password Reset vulnerability
9.8
40 minutes ago
Dataverse Integration< 2.91
Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure vulnerability
4.3
43 minutes ago
WP Events Manager< 2.2.5
Unauthenticated Payment Bypass and Booking Status Update via IDOR vulnerability
5.3
53 minutes ago
Five Star Restaurant Reservations< 2.7.23
Unauthenticated Payment Bypass and Booking Confirmation via IDOR vulnerability
5.3
53 minutes ago
Ninja Forms< 3.14.10
Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default vulnerability
5.3
55 minutes ago
miniOrange's Google Authenticator< 6.2.7
2FA Bypass via Password-Only Second-Factor Rebinding vulnerability
4.3
56 minutes ago
Contest Gallery< 30.0.7
Unauthenticated Login-Protection and 2FA Bypass via post_cg_login vulnerability
4.8
57 minutes ago
Event Booking Manager for WooCommerce (Pro)<= 5.0.2
Unauthenticated Price Manipulation vulnerability
5.3
58 minutes ago
Newsletters< 4.16
Unauthenticated API Authentication Bypass via Type Juggling vulnerability
4.8
59 minutes ago
Easy Booking – WooCommerce Booking &amp; Reservation Plugin< 3.5.0
Unauthenticated Minimum Booking Duration Bypass vulnerability
5.3
1 hour ago
WordPress File Upload< 5.1.7
File Overwrite via Race Condition vulnerability
5.4
1 hour ago
Contact Form by WPForms< 1.10.0.5
Unauthenticated PayPal Webhook Forgery vulnerability
5.3
1 hour ago
@tinacms/auth<= 1.1.3
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
1 hour ago
next-tinacms-azure<= 15.0.0
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
1 hour ago
@redocly/cli< 1.34.17
NPM: Redocly CLI: Path traversal when using `split` command
4.4
1 hour ago
@orpc/server<= 1.14.7
NPM: oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
6.3
1 hour ago
@cyclonedx/cyclonedx-npm< 6.0.0
NPM: @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
8.5
1 hour ago
@vendure/core< 3.7.0
NPM: Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
9.1
1 hour ago