Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,474
Mitigations
Mitigation rules
17,136
No official patch
13,360
In triage
1,391
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Ultimate Post Kit
<= 4.2.0
Cross-Site Scripting vulnerability
5.8
3 hours ago
APCu Manager
< 4.5.0
Unauthenticated Stored XSS via Cache Key Pollution vulnerability
7.1
3 hours ago
User Submitted Posts
< 20260608
Unauthenticated Stored XSS via Author Name vulnerability
7.1
4 hours ago
WP Support Plus Responsive Ticket System
<= 9.1.2
Unauthenticated Stored XSS via File Upload vulnerability
7.1
4 hours ago
Ultimate Member
< 2.12.0
Subscriber+ Stored XSS via Custom Textarea Profile Fields vulnerability
6.5
5 hours ago
Simple Membership
< 4.7.5
Unauthenticated Stored XSS via Stripe Webhook API Version vulnerability
7.1
6 hours ago
Taskbuilder
<= 5.0.7
Reflected Cross-Site Scripting vulnerability
7.1
6 hours ago
Asset CleanUp: Page Speed Booster
<= 1.4.0.5
Unauthenticated Stored Cross-Site Scripting via Comment Content vulnerability
7.1
6 hours ago
Pochipp
<= 1.20.2
Reflected Cross-Site Scripting via 'keyword' Parameter vulnerability
7.1
6 hours ago
Tutor LMS
<= 4.0.8
Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters vulnerability
7.1
6 hours ago
Login With OTP
<= 1.6
Unauthenticated Authentication Bypass vulnerability
9.8
6 hours ago
@file-viewer/doc
<= 2.3.0
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
2 days ago
msdoc-viewer
<= 0.2.1
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
2 days ago
adm-zip
< 0.6.1
NPM: adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
7.5
2 days ago
md-editor-v3
<= 6.5.3
NPM: md-editor-v3: XSS via fenced-code language rendering bypass
6.1
2 days ago
WP Magnific Popup
<= 1.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
2 days ago
Form Builder CP
< 1.2.47
Editor+ Stored XSS via form_structure vulnerability
6.5
2 days ago
KeepInMind Dashboard Notes
< 0.8.4.2
WordPress KeepInMind - Dashboard Notes plugin < 0.8.4.2 - Contributor+ Stored XSS vulnerability
6.5
2 days ago
Secure Copy Content Protection and Content Locking
< 5.1.5
Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter vulnerability
5.9
2 days ago
Store Locator WordPress
< 1.6.9
Admin+ Stored XSS via logo_name vulnerability
5.9
2 days ago
Load more