The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total46,434
Mitigations15,050
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Breeze<= 2.4.4
Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote vulnerability
10
43 minutes ago
ExactMetrics<= 9.1.2
Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process vulnerability
7.2
6 hours ago
WP Store Locator<= 2.2.261
Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta vulnerability
6.5
6 hours ago
Gutentor<= 3.5.5
WordPress Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor plugin <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML vulnerability
6.5
6 hours ago
Avada< 7.13.2
Cross Site Request Forgery (CSRF) vulnerability
4.3
17 hours ago
Order Minimum/Maximum Amount Limits for WooCommerce<= 4.6.4
Cross Site Scripting (XSS) vulnerability
6.5
17 hours ago
Maximum Products per User for WooCommerce<= 4.3.6
Cross Site Scripting (XSS) vulnerability
6.5
17 hours ago
Breaking News WP<= 1.3
Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read vulnerability
7.5
22 hours ago
Simple Random Posts Shortcode<= 0.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
22 hours ago
Emailchef<= 3.5.1
Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Settings Deletion vulnerability
5.4
23 hours ago
WP Responsive Popup + Optin<= 1.4
Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
7.1
23 hours ago
Create DB Tables<= 1.2.1
Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion vulnerability
9.1
23 hours ago
Sendmachine for WordPress<= 1.0.20
Unauthenticated SMTP Hijack to Privilege Escalation vulnerability
9.8
1 day ago
Short Comment Filter<= 2.2
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
Private WP suite<= 0.4.1
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
Real Estate Pro<= 1.0.9
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
HTTP Headers<= 1.19.2
Authenticated (Administrator+) CRLF Injection vulnerability
5.5
1 day ago
HTTP Headers<= 1.19.2
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
TextP2P Texting Widget<= 1.7
Cross-Site Request Forgery to Settings Update vulnerability
4.3
1 day ago
Kcaptcha<= 1.0.1
Cross-Site Request Forgery to Settings Update vulnerability
4.3
1 day ago