Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
39,321
Mitigations
Mitigation rules
14,611
No official patch
11,214
In triage
1,322
Published soon
34
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
Contextual Related Posts
< 4.2.2
Broken Access Control vulnerability
5.3
12 hours ago
Writeprint Stylometry
<= 0.1
Reflected Cross-Site Scripting via 'p' Parameter vulnerability
7.1
15 hours ago
[CR]Paid Link Manager
<= 0.5
Reflected Cross-Site Scripting vulnerability
7.1
15 hours ago
WP Go Maps
<= 10.0.05
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
6.5
15 hours ago
Duplicate Post
<= 4.5
Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability
5.4
19 hours ago
Subscriptions for WooCommerce
<= 1.9.2
Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability
5.3
19 hours ago
Royal Elementor Addons
<= 1.7.1049
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
5.3
19 hours ago
Booster for WooCommerce
< 7.11.3
Broken Access Control vulnerability
5.3
1 day ago
WowStore
<= 4.4.3
WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
9.3
1 day ago
NEX-Forms
<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id vulnerability
7.5
1 day ago
NEX-Forms
<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license vulnerability
4.3
2 days ago
WP User Frontend
<= 4.2.8
Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability
5.3
2 days ago
Wicked Folders
<= 4.1.0
Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion vulnerability
4.3
2 days ago
Thim Elementor Kit
<= 1.3.7
Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
5.3
2 days ago
Master Addons for Elementor
<= 2.1.3
Cross Site Scripting (XSS) vulnerability
5.9
2 days ago
WP EasyPay
<= 4.2.11
Broken Access Control vulnerability
5.4
2 days ago
Modern Events Calendar
<= 7.29.0
Broken Access Control vulnerability
5.3
2 days ago
Flexmls® IDX
<= 3.15.9
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Jannah
<= 7.6.3
Local File Inclusion vulnerability
8.1
2 days ago
LearnPress – Sepay Payment
<= 4.0.0
Broken Authentication vulnerability
7.5
2 days ago
Load more