Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
48,087
Mitigations
Mitigation rules
15,582
No official patch
12,951
In triage
1,539
Published soon
41
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Slideshow Gallery
<= 1.8.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
Fancy Testimonials
<= 1.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
13 hours ago
Appointment Booking Calendar
<= 1.4.01
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
4.3
14 hours ago
PowerPress Podcasting
<= 11.16.8
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
14 hours ago
UsersWP
<= 1.2.63
Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset vulnerability
2.7
14 hours ago
Customize My Account for WooCommerce
<= 4.3.6
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
Tutor LMS
<= 3.9.11
Authenticated (Administrator+) SQL Injection vulnerability
7.6
15 hours ago
Simple Membership
<= 4.7.5
Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation vulnerability
5.3
15 hours ago
Services Section block
<= 1.4.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
15 hours ago
PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin
<= 2.3.0
Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification vulnerability
4.3
15 hours ago
Orbit Fox by ThemeIsle
<= 3.0.6
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
15 hours ago
Advanced Order Export For WooCommerce
<= 4.0.10
Authenticated (Shop Manager+) SQL Injection vulnerability
7.6
15 hours ago
Gutenberg Blocks by Kadence Blocks
<= 3.7.5
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
4.3
16 hours ago
Form Maker by 10Web
<= 1.15.43
Authenticated (Adminsitrator+) SQL Injection vulnerability
8.5
16 hours ago
Form Maker by 10Web
<= 1.15.43
Authenticated (Administrator+) SQL Injection vulnerability
7.6
16 hours ago
Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets
<= 1.3.13.1
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
16 hours ago
Accessibility Checker by Equalize Digital
<= 1.42.1
Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification vulnerability
4.3
16 hours ago
e2pdf
<= 1.32.26
Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation vulnerability
8.8
17 hours ago
Dokan
<= 5.0.3
Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification vulnerability
4.3
17 hours ago
Optimole
<= 4.2.6
Cross-Site Request Forgery vulnerability
4.3
1 day ago
Load more