Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,404
Mitigations
Mitigation rules
17,499
No official patch
13,373
In triage
1,234
Published soon
49
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@a2ui/web_core
>= 0.9.0, < 0.10.2
NPM: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
9.3
28 minutes ago
trigger.dev
<= 4.5.8
NPM: Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
5.5
39 minutes ago
trigger.dev
<= 4.5.5
NPM: Trigger.dev: Cross-environment deployment cancel
5.4
41 minutes ago
trigger.dev
<= 4.5.5
NPM: Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
7.7
42 minutes ago
trigger.dev
<= 4.5.4
NPM: Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
5.3
44 minutes ago
trigger.dev
<= 4.5.5
NPM: Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
8.1
44 minutes ago
figlet
< 1.11.3
NPM: figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
8.2
45 minutes ago
trigger.dev
< 4.5.4
NPM: Trigger.dev: V1 coordinator default-secret unauth Socket.IO
9.2
45 minutes ago
trigger.dev
<= 4.5.1
NPM: Trigger.dev: Blind SSRF via alert-channel webhook
5.4
48 minutes ago
trigger.dev
<= 4.5.1
NPM: Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
7.1
48 minutes ago
Real Cookie Banner
<= 5.3.5
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Wp Social
<= 3.2.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
3 hours ago
ProfilePress
<= 4.17.4
Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
4.3
3 hours ago
ProfilePress
<= 4.17.4
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
Jeg Kit for Elementor
<= 3.2.19
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
SEOPress
<= 10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
3 hours ago
Burst Statistics
<= 3.7.1
Improper Authentication to Account Persistence vulnerability
4.3
3 hours ago
Beaver Builder
<= 2.11.0.5
Unauthenticated Arbitrary Shortcode Execution vulnerability
5.3
3 hours ago
Rich Showcase for Google Reviews
<= 7.1.3
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
3 hours ago
trigger.dev
< 4.5.2
NPM: Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
7.7
3 hours ago
Load more