The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total48,605
Mitigations15,656
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Slick Popup<= 1.7.15
Cross Site Scripting (XSS) vulnerability
6.5
3 minutes ago
Simple Basic Contact Form<= 20250114
Reflected XSS vulnerability
7.1
7 minutes ago
Infility Global< 2.15.19
Subscriber+ SQL Injection via order Parameter vulnerability
8.5
8 minutes ago
Tourfic<= 2.22.7
Unauthenticated SQL Injection vulnerability
9.3
11 minutes ago
SEOPress PRO<= 9.1.1
Broken Access Control vulnerability
4.3
16 minutes ago
Request a Quote<= 2.5.2
Cross Site Scripting (XSS) vulnerability
6.5
18 minutes ago
Slim SEO<= 4.6.2
Broken Access Control vulnerability
6.5
19 minutes ago
Gravity Forms Bookings premium<= 2.7.1
Authenticated (Subscriber+) Time-Based SQL Injection vulnerability
8.5
22 minutes ago
Dokan Pro<= 5.0.4
Unauthenticated SQL Injection vulnerability
9.3
23 minutes ago
Dokan Pro<= 5.0.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
28 minutes ago
SiteGround Email Marketing<= 1.7.5
Broken Access Control vulnerability
5.3
31 minutes ago
Frontend File Manager<= 23.6
Unauthenticated Arbitrary File Download vulnerability
7.5
48 minutes ago
Cornerstone< 7.8.9
Broken Access Control vulnerability
4.3
4 hours ago
Site Kit by Google< 1.176.0
Editor+ Email Reporting Settings Update vulnerability
3.8
5 hours ago
AI Share & Summarize< 2.0.4
Contributor+ Stored XSS via title_style Shortcode Attribute vulnerability
6.5
5 hours ago
Infility Global< 2.15.20
Editor+ SQL Injection via orderby Parameter vulnerability
8.5
5 hours ago
Essential Blocks for Gutenberg<= 6.1.4
Page Builder for Gutenberg Blocks & Patterns plugin <= 6.1.4 - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
17 hours ago
WP Meta SEO<= 4.5.18
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
18 hours ago
URL Preview<= 1.0
Unauthenticated Server-Side Request Forgery vulnerability
7.2
18 hours ago
Kargo Takip<= 1.2
Unauthenticated Server-Side Request Forgery vulnerability
7.2
18 hours ago