Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
39,630
Mitigations
Mitigation rules
14,793
No official patch
11,271
In triage
1,510
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
FloristPress
<= 7.8.2
Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability
7.1
17 minutes ago
JS Help Desk
<= 3.0.4
WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability
9.3
1 hour ago
SureForms
<= 2.5.2
Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
7.5
1 hour ago
Masteriyo - LMS
<= 2.1.6
Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability
8.8
1 hour ago
Responsive Plus
< 3.4.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
1 hour ago
WP Job Portal
<= 2.4.9
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
8.8
2 hours ago
ThemeREX Addons
< 2.38.5
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
Download Monitor
<= 5.1.7
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
5.3
2 hours ago
Twentig Supercharged Block Editor
<= 1.9.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability
6.5
2 hours ago
WP Lightbox 2
< 3.0.7
Admin+ Stored XSS vulnerability
5.9
2 hours ago
Conditional Menus
<= 1.2.6
Cross-Site Request Forgery to Menu Options Update vulnerability
4.3
2 hours ago
Complianz
<= 7.4.4.2
WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
6.5
2 hours ago
Elementor Website Builder
<= 3.35.7
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
4.3
2 hours ago
Ads by WPQuads
<= 2.0.98.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Ad Metadata Parameters vulnerability
6.5
2 days ago
PageLayer
<= 2.0.7
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
5.3
2 days ago
Ninja Forms
<= 3.14.1
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
6.5
2 days ago
Amelia
<= 9.1.2
Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change vulnerability
8.8
2 days ago
DSGVO snippet for Leaflet Map and its Extensions
<= 3.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute vulnerability
6.5
2 days ago
FormLift for Infusionsoft Web Forms
<= 7.5.21
Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow vulnerability
5.3
2 days ago
Blog2Social
<= 8.8.2
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability
4.3
2 days ago
Load more