The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,437
Mitigations17,088
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Price Drop Alert for WooCommerce<= 1.1
Unauthenticated SQL Injection vulnerability
9.3
50 minutes ago
Login/Signup Popup< 4.0.2
Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header vulnerability
8.1
1 hour ago
WCFM Marketplace<= 3.8.2
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
Login/Signup Popup< 4.0.2
Unauthenticated Account Takeover via Password Reset Code Brute Force vulnerability
8.1
2 hours ago
InfiniteWP Client< 1.13.6
Unauthenticated Administrator Account Takeover on Multisite vulnerability
8.1
2 hours ago
SoftMarket — Digital Marketplace<= 1.0.0
Unauthenticated Account Takeover via Email Verification Bypass vulnerability
9.8
2 hours ago
To Do List Member1.4-1.6
Unauthenticated Stored XSS, File Listing and Deletion vulnerability
8.8
2 hours ago
PuppyFW<= 0.4.4
Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation vulnerability
8.8
2 hours ago
Out-of-the-Box2.0-3.8.3
WordPress WP Cloud Plugins - Dropbox (Out-of-the-Box) plugin 2.0-3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
2 hours ago
Lets-Box2.0-3.8.3
WordPress WP Cloud Plugins - Box (Lets-Box) plugin 2.0-3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
2 hours ago
Share-one-Drive2.0-3.8.3
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
2 hours ago
Use-your-Drive2.0-3.8.3
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
2 hours ago
wpShopGermany IT-RECHT KANZLEI1.6-2.3
Unauthenticated RCE vulnerability
9
2 hours ago
Filter Gallery<= 1.1.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion vulnerability
8.1
2 hours ago
Login with QR<= 1.0.0
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
The Pressengine<= 1.0
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
Private Feed Key<= 0.1
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
Clean Login< 1.19
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
4 hours ago
All Bootstrap Blocks<= 1.3.31
Contributor+ Stored XSS vulnerability
7.1
4 hours ago
MasterStudy LMS3.6.2-3.7.49
Instructor+ Student PII Disclosure vulnerability
2.7
4 hours ago