Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,049
Mitigations
Mitigation rules
17,817
No official patch
13,558
In triage
1,046
Published soon
94
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
SMS Alert Order Notifications
3.6.4-4.0.0
Admin+ Network User Billing Phone Disclosure vulnerability
2.7
5 hours ago
Wallet System for WooCommerce
< 2.8.0
Subscriber+ Store-Wide Wallet Transaction Disclosure vulnerability
4.3
5 hours ago
BackWPup
< 5.7.7
Admin+ Path Traversal to RCE vulnerability
6.6
5 hours ago
BackWPup
3.3-5.7.6
Unauthenticated Backup Job Execution vulnerability
5.3
5 hours ago
Database Addon For WPForms ( wpforms entries )
< 1.1.1
Arbitrary Form Entry Deletion vulnerability
4.3
5 hours ago
LatePoint
< 5.7.3
Unauthenticated Customer PII Disclosure vulnerability
5.3
5 hours ago
LatePoint
< 5.6.5
Agent+ Arbitrary Order, Customer and Transaction Deletion vulnerability
2.7
5 hours ago
LatePoint
< 5.6.9
Agent+ Cross-Agent Data Disclosure and Modification vulnerability
3.3
5 hours ago
Booking Calendar
10.15-11.8.2
Editor+ Arbitrary Option Disclosure vulnerability
2.7
5 hours ago
Easy Digital Downloads
< 3.7.1
Subscriber+ Sensitive Information Disclosure vulnerability
4.3
5 hours ago
Booking Calendar
< 11.8
Unauthenticated Booking Information Disclosure and Modification vulnerability
4.8
5 hours ago
Image Photo Gallery Final Tiles Grid
< 3.6.14
Contributor+ Arbitrary Gallery Cloning, Image Modification and Post Meta Update vulnerability
2.7
5 hours ago
ghost
>= 6.56.0, < 6.67.0
NPM: Ghost: Remote Code Execution via Bookmark Card Images
8.8
15 hours ago
ghost
>= 6.34.0, < 6.67.0
NPM: Ghost: Stored XSS via Embed Card Previews
7.3
15 hours ago
ghost
>= 4.0.0, < 6.67.0
NPM: Ghost : Stored XSS via SVG Files in Content Imports
6.8
15 hours ago
ghost
>= 5.37.0, < 6.67.0
NPM: Ghost: Regular Expression Denial of Service in External Media Inliner
4.9
15 hours ago
ghost
>= 4.0.0, < 6.67.0
NPM: Ghost: Regular Expression Denial of Service in Content Import
4.9
15 hours ago
ghost
>= 6.54.1, < 6.65.0
NPM: Ghost: Server-Side Request Forgery in Bookmark Fetching
4
15 hours ago
ghost
>= 6.0.9, < 6.65.0
NPM: Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
4
15 hours ago
ghost
>= 4.22.0, < 6.65.0
NPM: Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
7.3
15 hours ago
Load more