Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,342
Mitigations
Mitigation rules
17,070
No official patch
13,361
In triage
1,351
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
CheckView Automated Testing
< 2.3.2
Administrator Account Creation via REST API Authentication Bypass vulnerability
9.8
27 minutes ago
Custom Fields
< 1.5.1
Unauthenticated Arbitrary File Deletion via Path Traversal vulnerability
8.6
28 minutes ago
Single Sign On For TNG
< 2.2.0
Unauthenticated Arbitrary Password Reset vulnerability
9.8
28 minutes ago
Dataverse Integration
< 2.91
Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure vulnerability
4.3
31 minutes ago
WP Events Manager
< 2.2.5
Unauthenticated Payment Bypass and Booking Status Update via IDOR vulnerability
5.3
41 minutes ago
Five Star Restaurant Reservations
< 2.7.23
Unauthenticated Payment Bypass and Booking Confirmation via IDOR vulnerability
5.3
41 minutes ago
Ninja Forms
< 3.14.10
Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default vulnerability
5.3
43 minutes ago
miniOrange's Google Authenticator
< 6.2.7
2FA Bypass via Password-Only Second-Factor Rebinding vulnerability
4.3
44 minutes ago
Contest Gallery
< 30.0.7
Unauthenticated Login-Protection and 2FA Bypass via post_cg_login vulnerability
4.8
45 minutes ago
Event Booking Manager for WooCommerce (Pro)
<= 5.0.2
Unauthenticated Price Manipulation vulnerability
5.3
46 minutes ago
Newsletters
< 4.16
Unauthenticated API Authentication Bypass via Type Juggling vulnerability
4.8
47 minutes ago
Easy Booking – WooCommerce Booking & Reservation Plugin
< 3.5.0
Unauthenticated Minimum Booking Duration Bypass vulnerability
5.3
49 minutes ago
WordPress File Upload
< 5.1.7
File Overwrite via Race Condition vulnerability
5.4
50 minutes ago
Contact Form by WPForms
< 1.10.0.5
Unauthenticated PayPal Webhook Forgery vulnerability
5.3
51 minutes ago
@tinacms/auth
<= 1.1.3
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
1 hour ago
next-tinacms-azure
<= 15.0.0
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
1 hour ago
@redocly/cli
< 1.34.17
NPM: Redocly CLI: Path traversal when using `split` command
4.4
1 hour ago
@orpc/server
<= 1.14.7
NPM: oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
6.3
1 hour ago
@cyclonedx/cyclonedx-npm
< 6.0.0
NPM: @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
8.5
1 hour ago
@vendure/core
< 3.7.0
NPM: Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
9.1
1 hour ago
Load more