Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,006
Mitigations
Mitigation rules
16,622
No official patch
13,334
In triage
1,039
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Everest Forms
< 3.5.0
Unauthenticated Missing Authorization via Site Assistant REST Endpoints vulnerability
5.3
5 minutes ago
SALESmanago & Leadoo
< 3.11.3
Subscriber+ SQL Injection vulnerability
8.5
5 minutes ago
Royal MCP
< 1.4.26
Subscriber+ Insufficient Authorization in MCP Tools vulnerability
8.1
12 minutes ago
Notifier
< 2.6
Subscriber+ LFI vulnerability
8.8
20 minutes ago
Printcart Web to Print Product Designer for WooCommerce
<= 2.8.5
Unauthenticated Folder Content Disclosure via Path Traversal vulnerability
5.3
26 minutes ago
Passster
< 4.3.9
Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass vulnerability
5.3
39 minutes ago
Charitable
< 1.8.12
Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass vulnerability
5.3
40 minutes ago
LitExtension: WooCommerce Migration Plugin
<= 1.2.5
Connector Token Takeover via CSRF vulnerability
4.3
41 minutes ago
myCred
< 3.2.5
Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED vulnerability
5.3
41 minutes ago
WP Event SOlution
< 4.1.21
Contributor+ Server-Side Request Forgery vulnerability
4.9
51 minutes ago
AI Engine
<= 3.6.0
WordPress AI Engine plugin 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools vulnerability
7.2
52 minutes ago
Drag and Drop Multiple File Upload – Contact Form 7
< 1.3.9.9
Unauthenticated RCE via Control Character Filename Bypass vulnerability
8.1
52 minutes ago
Duplicate Post
< 1.5.6
Authenticated Arbitrary Post Content and Password Disclosure vulnerability
4.3
56 minutes ago
Duplicate Post
< 1.5.6
Author+ Password-Protected Post Content Disclosure vulnerability
2.7
57 minutes ago
Media LIbrary Assistant
< 3.40
Author+ SQL Injection via mla_search_connector vulnerability
8.5
1 hour ago
Tamara Checkout
<= 1.9.9.20
Unauthenticated Order Status Manipulation vulnerability
5.3
1 hour ago
Dokan
< 5.0.14
Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount vulnerability
2.7
1 hour ago
Dokan
< 5.0.14
Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint vulnerability
5.3
1 hour ago
Link Whisper Free
< 0.9.7
Editor+ SQL Injection via domain Parameter vulnerability
8.5
1 hour ago
Drag and Drop Multiple File Upload – Contact Form 7
< 1.3.9.9
Admin+ Stored XSS via drag_n_drop_heading_tag Setting vulnerability
5.9
1 hour ago
Load more