The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total47,979
Mitigations15,520
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Hash Elements<= 1.5.4
Sensitive Data Exposure vulnerability
4.3
32 minutes ago
Fediverse Embeds<= 1.5.7
Unauthenticated SSRF vulnerability
7.2
12 hours ago
Fediverse Embeds<= 1.5.7
Unauthenticated SSRF vulnerability
5.4
17 hours ago
Speed Optimizer< 7.7.9
Unauthenticated Stored XSS via Minify Library vulnerability
7.1
1 day ago
Clearfy Cache< 2.4.2
Unauthenticated Stored XSS via Minify Library vulnerability
7.1
1 day ago
Autoptimize< 3.1.15
Unauthenticated Stored XSS via Minify Library vulnerability
7.1
1 day ago
Email Encoder Bundle< 2.4.7
Unauthenticated Stored XSS vulnerability
7.1
1 day ago
EventPress< 22.2
Reflected Cross-Site Scripting vulnerability
7.1
1 day ago
WP Maps< 4.9.3
Subscriber+ Local File Inclusion vulnerability
8.8
1 day ago
Ajax Load More< 7.8.4
Reflected XSS vulnerability
7.1
1 day ago
Decent Comments< 3.0.2
Unauthenticated Email Address Disclosure vulnerability
5.3
1 day ago
Presto Player<= 4.2.0
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 day ago
Restaurant Cafeteria<= 0.4.6
Subscriber+ Arbitrary Plugin Installation/Activation vulnerability
8.8
1 day ago
Fortis for WooCommerce< 1.3.1
Sensitive API Key Disclosure vulnerability
7.5
1 day ago
PowerPack for LearnDash< 1.3.0
Unauthenticated Arbitrary Option Update vulnerability
9.8
1 day ago
Magic Export & Import< 1.2.0
Unauthenticated PII Disclosure vulnerability
7.5
1 day ago
WP Photo Album Plus< 9.1.11.001
Unauthenticated SQL Injection via 'wppa-supersearch' Parameter vulnerability
9.3
1 day ago
Login with Salesforce<= 1.0.2
Unauthenticated Authentication Bypass vulnerability
8.1
1 day ago
WP eCommerce<= 3.15.1
Coupon Deletion via CSRF vulnerability
5.4
1 day ago
Feeds for YouTube< 2.6.4
Subscriber+ License Data Deletion vulnerability
5.4
1 day ago