The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,951
Mitigations14,874
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Blog2Social<= 8.8.3
Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Schedule Modification via 'b2s_id' Parameter vulnerability
4.3
7 hours ago
Awesome Support<= 6.3.7
Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter vulnerability
5.3
8 hours ago
Masteriyo - LMS<= 2.1.7
Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint vulnerability
5.3
8 hours ago
WP Blockade<= 0.9.14
Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'shortcode' Parameter vulnerability
6.5
8 hours ago
Pinterest Site Verification plugin using Meta Tag<= 1.8
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'post_var' vulnerability
6.5
8 hours ago
Gravity Forms <= 2.9.30
Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field vulnerability
7.1
8 hours ago
Gravity Forms <= 2.9.30
Reflected Cross-Site Scripting via 'form_ids' Parameter vulnerability
7.1
8 hours ago
Popup box< 5.5.0
Admin+ Stored Cross-Site Scripting (XSS) via CSRF vulnerability
7.1
8 hours ago
Attendance Manager<= 0.6.2
Authenticated (Subscriber+) SQL Injection via 'attmgr_off' Parameter vulnerability
8.5
8 hours ago
SQL Chart Builder< 2.3.8
Unauthenticated SQL Injection vulnerability
9.3
8 hours ago
DSGVO Google Web Fonts GDPR<= 1.1
Unauthenticated Arbitrary File Upload via 'fonturl' Parameter vulnerability
10
8 hours ago
Users manager – PN<= 1.1.15
WordPress Users manager - PN plugin <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action vulnerability
9.8
9 hours ago
Everest Forms<= 3.4.3
Unauthenticated PHP Object Injection via Form Entry Metadata vulnerability
9.8
9 hours ago
Smart Slider 3 PRO3.5.1.35
Backdoor vulnerability
10
9 hours ago
WP Visitor Statistics (Real Time Traffic)<= 8.4
Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute vulnerability
6.5
12 hours ago
Magic Conversation For Gravity Forms<= 3.0.97
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
12 hours ago
Element Pack Elementor Addons<= 8.4.2
Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget vulnerability
6.5
12 hours ago
Whole Enquiry Cart for WooCommerce<= 1.2.1
Authenticated (Administrator+) Stored Cross-Site Scripting via 'woowhole_success_msg' Parameter vulnerability
5.9
13 hours ago
pz-frontend-manager<= 1.0.6
Missing Authorization to Arbitrary User Deletion via 'dataType' Parameter vulnerability
5.3
14 hours ago
AM LottiePlayer<= 3.6.0
Authenticated (Author+) Stored Cross-Site Scripting via SVG vulnerability
5.9
14 hours ago