Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,652
Mitigations
Mitigation rules
16,877
No official patch
13,323
In triage
1,105
Published soon
33
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
JetPopup
<= 2.0.20.2
Broken Access Control vulnerability
5.3
28 minutes ago
WoodMart
< 8.3.8
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
WP Rentals
< 3.16.0
Insecure Direct Object References (IDOR) vulnerability
5.4
2 hours ago
WooCommerce
<= 10.9.4
SQL Injection vulnerability
7.6
3 hours ago
MarketKing
<= 2.1.60
Broken Access Control vulnerability
5.3
3 hours ago
WCFM Membership
<= 2.11.11
Broken Access Control vulnerability
5.3
3 hours ago
Divi Ajax Filter
<= 5.1.2
Unauthenticated Local File Inclusion vulnerability
9.8
3 hours ago
LearnDash LMS
<= 5.1.5
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
10
3 hours ago
toml
< 4.2.0
NPM: toml-node: Uncontrolled Recursion
7.5
14 hours ago
toml
< 4.1.2
NPM: toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
8.2
14 hours ago
phoenix
>= 1.2.0-rc.0, < 1.5.15
NPM: Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
6.3
14 hours ago
stream-json
<= 3.4.0
NPM: stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
6.2
14 hours ago
sanitize-html
<= 2.17.5
NPM: ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
6.1
15 hours ago
apostrophe
<= 4.31.0
NPM: ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
6.5
15 hours ago
@toon-format/toon
< 2.3.1
NPM: TOON: Prototype pollution when decoding untrusted TOON input
8.3
15 hours ago
claude-code-templates
<= 1.29.2
NPM: Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
8.8
15 hours ago
orval
< 8.21.0
NPM: Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
9.3
15 hours ago
orval
< 8.21.0
NPM: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
9.3
16 hours ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via schema default -> zod module-level template literal
9.3
16 hours ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via array-items default -> zod module-level template literal
9.3
16 hours ago
Load more