Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,485
Mitigations
Mitigation rules
16,369
No official patch
13,260
In triage
1,145
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Online Booking & Scheduling Calendar for WordPress by vcita
<= 4.6.0
Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter vulnerability
7.1
8 minutes ago
Profile Builder
<= 3.16.4
Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter vulnerability
9.8
1 hour ago
Object Sync for Salesforce
<= 2.2.13
Unauthenticated SQL Injection vulnerability
9.3
2 hours ago
6Storage Rentals
<= 2.27.0
Unauthenticated Account Takeover via 'email' Parameter vulnerability
9.8
2 hours ago
bLoyal
<= 3.1.611.78
Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings vulnerability
8.8
2 hours ago
RapiSafe – Secure Multi File Upload for Contact Form 7
<= 1.0.4
Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters vulnerability
8.6
2 hours ago
User Session Synchronizer
<= 1.4.0
Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters vulnerability
9.8
2 hours ago
Frontend Admin by DynamiApps
< 3.29.9
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Kirki
< 6.0.13
Unauthenticated SQL Injection vulnerability
9.3
3 hours ago
miniOrange's Google Authenticator
< 6.2.6
2FA Bypass vulnerability
8.1
3 hours ago
Pods
3.3-3.3.9
Unauthenticated Privilege Escalation vulnerability
9.8
2 days ago
@ooples/token-optimizer-mcp
< 5.1.0
NPM: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
5.3
2 days ago
@ooples/token-optimizer-mcp
< 5.1.0
NPM: Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
8.4
2 days ago
@budibase/server
< 3.41.3
Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
7.1
2 days ago
Extra Product Options & Add-Ons for WooCommerce
< 7.6
Arbitrary File Download vulnerability
7.5
2 days ago
Essential Real Estate
<= 5.3.3
PHP Object Injection vulnerability
8.8
2 days ago
FundEngine
<= 1.7.9
PHP Object Injection vulnerability
9.8
2 days ago
Theme Test Drive
<= 2.9.1
Local File Inclusion vulnerability
8.1
2 days ago
Vavo Core
<= 2.3.0
Local File Inclusion vulnerability
8.1
2 days ago
Quill Forms
<= 5.7.1
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Load more