Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,009
Mitigations
Mitigation rules
17,321
No official patch
13,363
In triage
1,413
Published soon
32
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Easy Pricing Tables
<= 4.1.2
SQL Injection vulnerability
8.5
1 minute ago
Two Factor
<= 0.16.0
Denial of Service Attack vulnerability
5.3
5 minutes ago
Prevent files / folders access
<= 2.6.7
Broken Access Control vulnerability
4.3
7 minutes ago
Astra WordPress Theme
<= 4.13.12
Content Injection vulnerability
2.7
13 minutes ago
Virtue Premium
<= 4.10.22
Cross Site Scripting (XSS) vulnerability
6.5
33 minutes ago
Virtue Premium
<= 4.10.21
Cross Site Scripting (XSS) vulnerability
6.5
35 minutes ago
ReactPress
<= 3.4.0
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
54 minutes ago
Real Estate Manager
<= 7.3
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
58 minutes ago
Frontend Post Submission Manager Lite
<= 1.3.4
Unauthenticated Stored DOM-Based Cross-Site Scripting vulnerability
7.1
1 hour ago
Post Views Stats Counter
<= 1.1.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Product Designer App
<= 1.1.3
Unauthenticated Arbitrary File Read vulnerability
7.5
1 hour ago
Simply Schedule Appointments
<= 1.6.12.27
Authenticated (Subscriber+) Local File Inclusion vulnerability
7.5
1 hour ago
@nestjs/microservices
< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
8 hours ago
fast-uri
< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
8 hours ago
fast-uri
>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
8 hours ago
@xhmikosr/decompress
<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
decompress
<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
ip-address
<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
8 hours ago
ip-address
<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
8 hours ago
moment
>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
8 hours ago
Load more