Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,162
Mitigations
Mitigation rules
16,153
No official patch
13,200
In triage
1,141
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Simple Backup
<= 2.7.11
Unauthenticated Arbitrary File Download vulnerability
7.5
4 minutes ago
BuddyPress
<= 14.5.0
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
6 minutes ago
Dharma Booking
<= 2.28.3
Unauthenticated Local File Inclusion vulnerability
8.1
18 minutes ago
Membership by Supsystic
<= 1.4.7
Unauthenticated SQL Injection vulnerability
9.3
26 minutes ago
Product Catalog 8
<= 1.2.0
SQL Injection vulnerability
9.3
28 minutes ago
404 SEO Redirection
<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
29 minutes ago
WP Google Review Slider
<= 6.1
Unauthenticated SQL Injection vulnerability
9.3
30 minutes ago
BBS e-Franchise
< 1.1.4
SQL Injection vulnerability
9.3
33 minutes ago
WordPress Survey & Poll
<= 1.5.7.3
Unauthenticated SQL Injection vulnerability
9.3
35 minutes ago
Wow Viral Signups
<= 2.1
Unauthenticated SQL Injection vulnerability
9.3
39 minutes ago
Flights & Hotels Booking WP Plugin
<= 2.3
Unauthenticated SQL Injection vulnerability
9.3
40 minutes ago
PICA Photo Gallery
<= 1.0
SQL Injection vulnerability
9.3
43 minutes ago
KittyCatfish
<= 2.2
Unauthenticated SQL Injection vulnerability
9.3
50 minutes ago
Car Park Booking System for WordPress
<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
51 minutes ago
FleekDash V2
<= 2.6.2.2
Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover vulnerability
8.8
53 minutes ago
@apostrophecms/seo
<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
2 days ago
apostrophe
<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
2 days ago
apostrophe
<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
2 days ago
sanitize-html
>= 1.18.0, <= 2.17.4
NPM: sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
5.4
2 days ago
@nocobase/plugin-notification-in-app-message
<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
2 days ago
Load more