Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,958
Mitigations
Mitigation rules
16,598
No official patch
13,325
In triage
1,076
Published soon
33
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
jsonata
< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
1 hour ago
jsonata
< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
1 hour ago
jsonata
<= 1.8.7
NPM: JSONata: Arbitrary Code Execution via crafted JSONata expressions
9.3
1 hour ago
@keystone-6/core
<= 6.5.2
NPM: Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
7.5
1 hour ago
defuddle
<= 0.19.0
NPM: Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
8.2
1 hour ago
unleash-server
< 8.0.3
NPM: Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
4.1
3 hours ago
unleash-server
< 7.5.2
NPM: Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
5.5
3 hours ago
unleash-server
< 7.5.2
NPM: Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
7.5
3 hours ago
Wawp
<= 4.8.6
Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure vulnerability
9.8
12 hours ago
WPForms Pro
<= 2.0.0.2
Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values vulnerability
7.1
12 hours ago
JSON Options
<= 0.0.4
Unauthenticated Arbitrary Options Update vulnerability
9.8
12 hours ago
Depicter Slider
< 4.8.0
Editor+ Arbitrary File Upload via ZIP Import vulnerability
9.1
12 hours ago
Kirki
< 6.2.3
Editor+ Stored XSS via Font Zip Upload vulnerability
6.5
12 hours ago
GutenKit
<= 2.4.15
Contributor+ Mailchimp Audience Data Disclosure vulnerability
4.3
12 hours ago
Admin and Site Enhancements (ASE)
< 9.0.1
Author+ Stored XSS via SVG Upload over XML-RPC vulnerability
5.9
12 hours ago
GutenKit
< 2.5.0
Author+ Stored XSS via SVG Upload vulnerability
5.9
12 hours ago
Royal Elementor Addons
< 1.7.1066
Admin+ Remote Code Execution via Widget Builder vulnerability
7.2
12 hours ago
SG AI Studio
<= 1.2.7
Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint vulnerability
4.3
12 hours ago
Events Made Easy
<= 3.2.5
Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property vulnerability
7.5
12 hours ago
Membership For WooCommerce
< 3.1.2
Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass vulnerability
5.3
12 hours ago
Load more