The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,408
Mitigations14,671
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
EmailKit<= 1.6.3
Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter vulnerability
4.9
11 minutes ago
Contact List<= 3.0.18
Authenticated (Contributor+) Stored Cross-Site Scripting via '_cl_map_iframe' Parameter vulnerability
6.5
2 hours ago
Keep Backup Daily<= 2.1.2
Authenticated (Admin+) Stored Cross-Site Scripting via Backup Title vulnerability
5.9
2 hours ago
Keep Backup Daily<= 2.1.1
Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter vulnerability
2.7
2 hours ago
Alt Manager<= 1.8.2
Authenticated (Author+) Stored Cross-Site Scripting via Post Title vulnerability
5.9
3 hours ago
KiviCare<= 4.1.2
WordPress KiviCare - Clinic & Patient Management System (EHR) plugin <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token vulnerability
9.8
13 hours ago
KiviCare<= 4.1.2
Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard vulnerability
8.2
13 hours ago
Post SMTP<= 3.8.0
Unauthenticated Stored Cross-Site Scripting via 'event_type' vulnerability
7.1
13 hours ago
Slimstat Analytics<= 5.3.5
Unauthenticated Stored Cross-Site Scripting via 'fh' vulnerability
7.1
13 hours ago
Restrict Content<= 3.2.24
WordPress Membership Plugin - Restrict Content plugin <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirect vulnerability
4.3
14 hours ago
Simply Schedule Appointments<= 1.6.10.0
Unauthenticated SQL Injection via 'fields' Parameter vulnerability
9.3
14 hours ago
Aimogen Pro<= 2.7.5
Unauthenticated Privilege Escalation via Arbitrary Function Call vulnerability
9.8
14 hours ago
ilGhera Carta Docente for WooCommerce<= 1.5.0
Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter vulnerability
6.5
21 hours ago
CM Custom WordPress Reports and Analytics<= 1.2.7
Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels vulnerability
5.9
21 hours ago
RockPress<= 1.0.17
Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via AJAX Actions vulnerability
5.4
21 hours ago
Instant Popup Builder<= 1.1.7
Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter vulnerability
5.3
1 day ago
Add Custom Fields to Media<= 2.0.3
Cross-Site Request Forgery to Custom Field Deletion via 'delete' Parameter vulnerability
4.3
1 day ago
Draft List<= 2.6.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'display_name' Parameter vulnerability
5.9
1 day ago
Download Manager<= 3.3.49
Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability
4.3
1 day ago
Info Cards<= 2.0.7
Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes vulnerability
6.5
1 day ago