The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,290
Mitigations17,444
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
SiteOrigin Widgets Bundle<= 1.73.2
Authenticated (Contributor+) Local File Inclusion vulnerability
7.5
15 minutes ago
JetAppointment<= 2.5.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
20 minutes ago
Avada<= 7.16.1
Reflected Cross-Site Scripting vulnerability
7.1
27 minutes ago
Forminator<= 1.57.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
38 minutes ago
JSON API Auth<= 3.1.2
Unauthenticated Authentication Bypass vulnerability
9.8
55 minutes ago
Divi Membership<= 2.2.0
Unauthenticated Privilege Escalation via 'form_id' Parameter vulnerability
9.8
1 hour ago
Divi Membership<= 2.3.0
Unauthenticated Authentication Bypass via 'paypal_param' Parameter vulnerability
9.8
1 hour ago
WPMobile.App<= 11.82
Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter vulnerability
9.8
2 hours ago
Otter - Gutenberg Block<= 3.2.6
Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget vulnerability
3.1
12 hours ago
Listdom<= 6.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
LatePoint<= 5.7.1
Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration vulnerability
5.3
12 hours ago
MultiVendorX<= 5.0.18
Authenticated (Store Manager+) SQL Injection vulnerability
6.5
12 hours ago
Ninja Forms<= 3.15.4
Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission vulnerability
7.1
14 hours ago
Ninja Forms File Uploads Extension<= 3.3.34
WordPress Ninja Forms - File Uploads plugin <= 3.3.34 - Unauthenticated Arbitrary File Upload vulnerability
10
14 hours ago
Super Forms<= 6.3.316
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
14 hours ago
Super Forms<= 6.3.316
Unauthenticated Path Traversal to Arbitrary File Read vulnerability
7.5
14 hours ago
DevKit Pro<= 2.3.0
Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow vulnerability
9.8
15 hours ago
CTX Feed Pro<= 7.6.12
Authenticated (Administrator+) Remote Code Execution vulnerability
7.2
15 hours ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
6.8
15 hours ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9.9
15 hours ago