The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total47,630
Mitigations15,334
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<= 2.0.8
SQL Injection vulnerability
8.5
04/06/2026
Sunshine Photo Cart<= 3.6.7
Broken Access Control vulnerability
6.3
02/06/2026
SePay Gateway<= 1.1.20
Sensitive Data Exposure vulnerability
6.5
02/06/2026
Advanced Custom Fields<= 6.8.1
Unauthenticated Broken Access Control vulnerability
5.3
1 hour ago
affiliate-toolkit<= 3.8.4
Authenticated (Editor+) Remote Code Execution vulnerability
7.2
2 hours ago
Booking Calendar – Event Calendar<= 2.1.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Query Shortcode<= 0.2.1
Authenticated (Contributor+) Local File Inclusion vulnerability
7.5
2 hours ago
NS Product icon badge<= 1.2.4
Reflected Cross-Site Scripting vulnerability
6.1
2 hours ago
Livemesh SiteOrigin Widgets<= 3.9.2
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
2 hours ago
Livemesh Addons for WPBakery Page Builder<= 3.9.4
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
2 hours ago
Livemesh Addons for Beaver Builder<= 3.9.2
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
2 hours ago
Enable jQuery Migrate Helper<= 1.4.1
Missing Authorization to Authenticated (Subscriber+) jQuery Version Downgrade vulnerability
6.5
2 hours ago
WPCode<= 2.3.5
Authenticated (Author+) Remote Code Execution vulnerability
8.8
2 hours ago
Firebase Support & Chat Management<= 3.1.1
Missing Authorization to Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Login with NEAR<= 0.3.3
Authentication Bypass vulnerability
8.1
2 hours ago
Boost<= 2.0.3
Unauthenticated PHP Object Injection vulnerability
9.8
2 hours ago
Master Slider<= 3.10.8
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
GenerateBlocks<= 2.1.0
Sensitive Data Exposure vulnerability
6.5
2 hours ago
Xpro Elementor Addons - Pro<= 1.4.7
WordPress Xpro Elementor Addons - Pro plugin <= 1.4.7 - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read vulnerability
6.5
14 hours ago
MinhNhut Link Gateway<= 3.6.1
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
4.4
14 hours ago