The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,854
Mitigations13,236
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Ultimate Member<= 2.11.0
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' vulnerability
6.5
6 hours ago
Demo Importer Plus<= 2.0.8
Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation vulnerability
8.8
6 hours ago
OpenID Connect Generic Client<= 3.10.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
15 hours ago
NextGEN Gallery<= 3.59.12
Authenticated (Contributor+) Local File Inclusion via 'template' vulnerability
8.8
15 hours ago
Events Manager<= 7.2.2.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode vulnerability
6.5
15 hours ago
Embed Any Document<= 2.7.10
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
15 hours ago
Page Builder: Live Composer<= 2.0.2
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
6.5
15 hours ago
Ultimate Member<= 2.11.0
Authenticated (Subscriber+) Profile Privacy Setting Bypass vulnerability
4.3
15 hours ago
HTML Forms<= 1.6.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 day ago
Zephyr Project Manager<= 3.3.203
Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery vulnerability
4.9
1 day ago
BP Better Messages<= 2.10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 day ago
WP Social Ninja<= 4.0.1
Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification vulnerability
6.5
1 day ago
Ninja Forms<= 3.13.2
Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token vulnerability
7.5
1 day ago
Download Plugins and Themes from Dashboard<= 1.9.6
Cross-Site Request Forgery to Bulk Plugin/Theme Archival vulnerability
4.3
1 day ago
Converter for Media<= 6.3.2
Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint vulnerability
4.3
1 day ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.0.7
Missing Authorization to Unauthenticated Arbitrary Post Deletion vulnerability
5.3
1 day ago
WP Recipe Maker<= 10.2.3
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
1 day ago
Essential Addons for Elementor<= 6.5.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 day ago
Essential Blocks for Gutenberg<= 5.7.2
Missing Authorization To Authenticated (Author+) Information Disclosure vulnerability
4.3
1 day ago
WP to LinkedIn Auto Publish<= 1.9.8
Reflected Cross-Site Scripting via PostMessage vulnerability
7.1
1 day ago