Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,479
Mitigations
Mitigation rules
16,360
No official patch
13,257
In triage
1,138
Published soon
10
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Pods
3.3-3.3.9
Unauthenticated Privilege Escalation vulnerability
9.8
1 day ago
@ooples/token-optimizer-mcp
< 5.1.0
NPM: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
5.3
1 day ago
@ooples/token-optimizer-mcp
< 5.1.0
NPM: Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
8.4
1 day ago
@budibase/server
< 3.41.3
Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
7.1
1 day ago
Starter Templates by Kadence WP
<= 2.3.3
Denial of Service Attack vulnerability
7.5
2 days ago
Site Reviews
<= 8.2.0
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
CTX Feed
<= 6.6.46
Arbitrary File Download vulnerability
4.9
2 days ago
OttoKit
<= 1.1.35
Server Side Request Forgery (SSRF) vulnerability
7.2
2 days ago
GiveWP
<= 4.16.5.1
Broken Access Control vulnerability
6.5
2 days ago
GiveWP
< 4.16.6
Broken Access Control vulnerability
6.5
2 days ago
Breeze
<= 2.5.12
Arbitrary Content Deletion vulnerability
8.2
2 days ago
Templately
<= 3.7.1
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Epeken All Kurir
<= 2.1.2
Unauthenticated Order Payment Confirmation Forgery vulnerability
3.7
2 days ago
Paymob for WooCommerce
< 4.1.9
Unauthenticated SQL Injection via Paymob Callback Pixel Lookup vulnerability
9.3
2 days ago
WishList Member X
<= 3.34.1
Unauthenticated Account Takeover via 'mergewith' Parameter vulnerability
9.8
2 days ago
Embed Google Photos album
<= 2.2.1
Contributor+ Stored XSS via link Shortcode Attribute vulnerability
6.5
2 days ago
Bit Form
<= 3.2.0
Authenticated (Administrator+) SQL Injection via 'filterText' Parameter vulnerability
7.6
2 days ago
affiliate-toolkit
<= 3.8.8
Authenticated (Administrator+) SQL Injection via 'orderby' Parameter vulnerability
7.6
2 days ago
Astro Booking Engine
<= 1.4.0
Cross-Site Request Forgery to Settings Reset vulnerability
5.4
2 days ago
W3 Total Cache
<= 2.10.3
Unauthenticated Stored Cross-Site Scripting via Comment Author Name vulnerability
7.1
2 days ago
Load more