Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,963
Mitigations
Mitigation rules
16,976
No official patch
13,351
In triage
1,216
Published soon
27
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP Express Checkout (Accept PayPal Payments)
< 2.5.0
Unauthenticated Payment Bypass vulnerability
5.3
2 hours ago
Spam protection, AntiSpam, FireWall by CleanTalk
< 6.87
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
3 hours ago
SupportCandy
3.2.9-3.5.2
Unauthenticated Ticket Attachment Disclosure vulnerability
5.3
3 hours ago
Payment Plugins for PayPal WooCommerce
< 2.0.26
Subscriber+ Stored Payment Method Assignment vulnerability
5.9
3 hours ago
iTracker360
<= 2.2.0
Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field vulnerability
6.1
3 hours ago
Quentn WP
1.2.13-1.2.14
Unauthenticated SQLi vulnerability
9.3
3 hours ago
Loops & Logic
< 4.3.0
Unauthenticated User Data and Site Option Disclosure vulnerability
7.5
3 hours ago
ELEX WooCommerce Request a Quote
< 2.4.1
Unauthenticated SQLi vulnerability
9.3
3 hours ago
Chat Help
<= 3.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
7.5
3 hours ago
Business Intelligence Lite
<= 3.2.0
Authenticated (Subscriber+) Missing Authorization to Privilege Escalation vulnerability
8
3 hours ago
Direct Download for WooCommerce
<= 1.19
Unauthenticated Arbitrary File Read vulnerability
7.5
3 hours ago
Bulk Password Reset
<= 1.3.3
Authenticated (Subscriber+) Arbitrary Password Reset vulnerability
8.8
4 hours ago
@openhop/server
<= 0.3.5
NPM: @openhop/server: Path Traversal in Flow ID File Operations
8.3
10 hours ago
functype-mcp-server
<= 1.4.3
NPM: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
7.8
10 hours ago
@yeger/turbo-graph
<= 2.8.8
NPM: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
8.8
10 hours ago
nuxt-ollama
>= 1.2.26, < 1.3.1
NPM: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
7.5
10 hours ago
Aruba HiSpeed Cache
<= 3.0.14
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
smol-toml
<= 1.7.0
NPM: smol-toml: Denial of Service via malformed TOML documents
8.2
16 hours ago
Easy Google Fonts
<= 2.0.4
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
6.5
19 hours ago
Advanced Contact form 7 DB
<= 2.1.3
Missing Authorization to Authenticated (Custom+) Unauthorized Data Import vulnerability
4.3
19 hours ago
Load more