Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,356
Mitigations
Mitigation rules
16,300
No official patch
13,241
In triage
1,124
Published soon
29
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WordPress
<= 7.0.3
Authenticated (Author+) File Type Confusion to Remote Code Execution vulnerability
9.1
4 hours ago
GiveWP
< 4.16.6
Cross Site Scripting (XSS) vulnerability
6.5
7 hours ago
Revolut Gateway for WooCommerce
< 4.22.10
Broken Access Control vulnerability
5.3
7 hours ago
GiveWP
< 4.16.6
Broken Access Control vulnerability
5.3
8 hours ago
MailChimp For WooCommerce
< 6.2
SQL Injection vulnerability
7.6
8 hours ago
WP Data Access
<= 5.5.79
Cross Site Scripting (XSS) vulnerability
5.9
8 hours ago
Featured Image from URL
<= 5.3.3
Cross Site Scripting (XSS) vulnerability
6.5
8 hours ago
Ninja Tables Pro
5.2.11
Backdoor vulnerability
10
9 hours ago
Fluent Forms Pro Add On Pack
6.2.7
Backdoor vulnerability
10
10 hours ago
Formidable Digital Signatures
<= 3.0.6
Unauthenticated Arbitrary File Deletion via Signature Field vulnerability
8.6
12 hours ago
Passwordless Login by VentraConnect
<= 1.4.3
WordPress Social Login, Passkeys, Magic Link & Email OTP - Passwordless Login by VentraConnect plugin <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback vulnerability
8.1
13 hours ago
Frontend Admin by DynamiApps
<= 3.29.9
Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token vulnerability
8.8
1 day ago
Ray Enterprise Translation
<= 1.7.3
Subscriber+ Language Addition and Deletion vulnerability
5.4
1 day ago
GeoDirectory
<= 2.8.169
Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision vulnerability
8.1
1 day ago
InstaWP Connect
<= 0.1.3.6
Unauthenticated Cryptographic Key Disclosure vulnerability
5.9
1 day ago
AcyMailing SMTP Newsletter
<= 10.11.1
Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update vulnerability
8.8
1 day ago
Tablesome
<= 1.2.9
SQL Injection vulnerability
9.3
1 day ago
Ultimate Store Kit Elementor Addons
<= 3.0.7
Cross-Site Scripting vulnerability
7.1
1 day ago
Element Pack Elementor Addons
<= 8.7.14
Cross-Site Scripting vulnerability
7.1
1 day ago
Live Copy Paste for Elementor
<= 1.5.4
Cross-Site Scripting vulnerability
7.1
1 day ago
Load more