The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,712
Mitigations16,886
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@typespec/spector<= 0.1.0-alpha.26
NPM: TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
7.5
34 minutes ago
WP File Download<= 6.3.8
Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter vulnerability
6.5
2 hours ago
Abandoned Cart Pro for WooCommerce<= 10.7.1
Missing Authorization to Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Gravity Forms<= 2.10.5
Unauthenticated Stored Cross-Site Scripting via Post Body Field Value vulnerability
7.1
2 hours ago
W3 Total Cache<= 2.10.5
Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator vulnerability
7.1
2 hours ago
Ninja Forms<= 3.15.1
Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key vulnerability
7.1
2 hours ago
Spam protection, AntiSpam, FireWall by CleanTalk<= 6.86
Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder vulnerability
7.1
2 hours ago
Divi<= 4.27.6
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter vulnerability
6.5
3 hours ago
Divi<= 4.27.6
Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter vulnerability
4.9
3 hours ago
Hummingbird<= 3.21.0
WordPress Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN plugin <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log vulnerability
9
3 hours ago
DearFlip<= 2.4.30
Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute vulnerability
6.5
3 hours ago
Theme My Login<= 7.1.15
Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage vulnerability
4.3
3 hours ago
MStore API<= 4.20.0
Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery vulnerability
9.8
3 hours ago
DearFlip<= 2.4.30
Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML vulnerability
6.5
3 hours ago
WP Social Chat<= 8.6.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box vulnerability
6.5
3 hours ago
Welcart e-Commerce<= 2.12.1
Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback vulnerability
8.6
3 hours ago
Events Manager<= 7.3.3
WordPress Events Manager - Calendar, Bookings, Tickets, and more! plugin <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes vulnerability
5.9
3 hours ago
deepseek-tui>= 0.8.6, < 0.8.41
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
4 hours ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
4 hours ago
deepseek-tui>= 0.8.33, < 0.8.41
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
4 hours ago