Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,490
Mitigations
Mitigation rules
16,840
No official patch
13,328
In triage
1,129
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Broken Link Checker
<= 2.4.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
FluentCart
<= 1.6.2
Authenticated (Custom+) Arbitrary File Deletion vulnerability
7.7
1 hour ago
WP Project Manager Pro
<= 4.0.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
2 hours ago
Måne
<= 1.7
Unauthenticated Local File Inclusion vulnerability
8.1
2 hours ago
WordPress Persistent Login
<= 3.1.0
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
2 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
<= 4.4.1
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
TranslatePress
<= 3.3.1
Unauthenticated Account Takeover vulnerability
9.8
2 hours ago
Formidable Charts
<= 2.0.1
Unauthenticated Arbitrary File Read via 'frm_graph' Parameter vulnerability
7.5
2 hours ago
sanitize-html
>= 1.9.0, <= 2.17.6
NPM: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
5.4
11 hours ago
nanoid
< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
13 hours ago
pnpm
>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
13 hours ago
Easy Waveform Player
<= 1.2.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
pnpm
>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
13 hours ago
@appium/base-driver
<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
13 hours ago
Divi
<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
14 hours ago
SigmaForms Pro – AI Generated Forms
<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
15 hours ago
DevKit Pro
<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
15 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
7.5
15 hours ago
browserslist
<= 4.28.6
NPM: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
7.5
15 hours ago
mysql2
< 3.22.0
NPM: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
8.2
15 hours ago
Load more