The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,821
Mitigations13,214
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
OneSignal – Web Push Notifications<= 3.6.1
Missing Authorization to Unauthenticated Plugin Settings Update vulnerability
5.3
38 minutes ago
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress<= 2.0.3
WordPress FluentAuth - Auth Security Plugin plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode vulnerability
6.5
38 minutes ago
RegistrationMagic<= 6.0.6.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode vulnerability
6.5
39 minutes ago
CC Child Pages<= 2.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'child_pages' Shortcode vulnerability
6.5
40 minutes ago
User Registration<= 4.4.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
41 minutes ago
Filebird<= 6.5.1
Missing Authorization to Authenticated (Author+) Global Folders Tampering vulnerability
4.3
46 minutes ago
Lightweight Accordion<= 1.5.20
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
4 hours ago
Elementor Addon Elements<= 1.14.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
5 hours ago
HandL UTM Grabber<= 2.8.0
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
JetWidgets For Elementor<= 1.0.20
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets vulnerability
6.5
5 hours ago
MinimogWP<= 3.9.6
Local File Inclusion vulnerability
7.5
2 days ago
Restrict Elementor Widgets, Columns and Sections<= 1.12
Broken Access Control vulnerability
4.3
2 days ago
Turitor< 1.5.3
Local File Inclusion vulnerability
7.5
2 days ago
Digiqole< 2.2.7
Local File Inclusion vulnerability
7.5
2 days ago
Brizy<= 2.7.16
Authenticated (Contributor+) Sensitive Information Exposure via get_users Function vulnerability
6.5
2 days ago
King Addons for Elementor<= 51.1.39
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets vulnerability
6.5
2 days ago
Marquee Addons for Elementor<= 2.4.3
Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget vulnerability
6.5
2 days ago
Enter Addons<= 2.2.7
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and Image Comparison Widgets vulnerability
6.5
2 days ago
Popup Builder<= 4.4.1
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
2 days ago
Livemesh SiteOrigin Widgets<= 3.9.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Hero Header and Pricing Table Widgets vulnerability
6.5
2 days ago