Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,157
Mitigations
Mitigation rules
17,390
No official patch
13,357
In triage
1,364
Published soon
37
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Social Media & Share Icons
<= 3.0.1
Reflected DOM-Based Cross-Site Scripting vulnerability
7.1
8 minutes ago
Simply Schedule Appointments
<= 1.6.12.31
Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure vulnerability
6.5
14 minutes ago
LatePoint
<= 5.7.0
Unauthenticated Arbitrary Shortcode Execution vulnerability
5.3
23 minutes ago
Redux Framework
<= 4.5.14
Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion vulnerability
4.3
2 hours ago
Advanced Woo Labels
<= 2.51
Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
2 hours ago
AI Engine
<= 3.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Extendify
<= 3.1.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
ClearSale Total
<= 3.4.2
Unauthenticated SQL Injection vulnerability
9.3
2 hours ago
Simply Schedule Appointments
<= 1.6.12.32
Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion vulnerability
7.5
2 hours ago
Zella Theme
< 2.6.3
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
WP User Frontend
3.5.29-4.3.11
Unauthenticated Privilege Escalation vulnerability
7.4
2 hours ago
ByteCoreStack – MCP Connector for AI Tools
<= 1.2.3
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Super Forms
<= 6.3.316
Unauthenticated Privilege Escalation vulnerability
9.8
2 hours ago
Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform
<= 2.15.0
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
WPC Shop as a Customer for WooCommerce
<= 2.0.0
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
3 hours ago
Super Forms
<= 6.3.316
Authenticated (Subscriber+) Arbitrary File/Directory Deletion vulnerability
8.6
3 hours ago
fastify
< 5.12.5
NPM: fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
5.9
10 hours ago
hono
< 4.13.7
NPM: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
4.7
10 hours ago
fastify
< 5.12.2
NPM: fastify vulnerable to request body replacement via an async validation result collision
8.1
10 hours ago
fastify
>= 4.0.0, < 5.12.2
NPM: fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
7.5
10 hours ago
Load more