The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total38,297
Mitigations14,044
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Easy Social Feed<= 6.5.2
Missing Authorization to Settings Modification vulnerability
4.3
1 hour ago
Backup Migration<= 1.3.9
Authenticated (Admin+) OS Command Injection via url vulnerability
7.2
1 hour ago
Auto Featured Image (Auto Post Thumbnail)<= 4.1.7
Authenticated (Author+) Server-Side Request Forgery vulnerability
6.4
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'pt_cancel_subscription' vulnerability
5.4
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'update_profile_preference' vulnerability
5.4
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'paytium_sw_save_api_keys' vulnerability
5.4
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'check_for_verified_profiles' vulnerability
4.3
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'paytium_notice_dismiss' vulnerability
4.3
1 hour ago
Paytium<= 4.3.7
Missing Authorization in 'check_mollie_account_details' vulnerability
4.3
1 hour ago
personal-authors-category<= 0.3
Reflected Cross-Site Scripting vulnerability
7.1
8 hours ago
Secure Copy Content Protection and Content Locking<= 4.9.8
Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header vulnerability
7.1
8 hours ago
Customer Reviews for WooCommerce<= 5.97.0
Unauthenticated Stored Cross-Site Scripting via media[].href Parameter vulnerability
7.1
8 hours ago
WP System Log<= 1.2.8
Missing Authorization to Sensitive Information Exposure via Log File vulnerability
6.5
9 hours ago
Converter for Media<= 6.5.1
WordPress Converter for Media - Optimize images | Convert WebP & AVIF plugin <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src vulnerability
7.2
10 hours ago
Uni CPO (Premium)<= 4.9.60
WordPress Product Options and Price Calculation Formulas for WooCommerce - Uni CPO (Premium) plugin <= 4.9.60 - Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion vulnerability
5.8
12 hours ago
BlueSnap Payment Gateway for WooCommerce<= 3.3.0
Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation vulnerability
7.5
12 hours ago
Truelysell Core<= 1.8.7
Unauthenticated Privilege Escalation via Registration vulnerability
9.8
12 hours ago
wpForo Forum<= 2.4.13
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
12 hours ago
Magic Login Mail or QR Code<= 2.05
Unauthenticated Privilege Escalation via Insecure QR Code File Storage vulnerability
8.1
21 hours ago
midi-Synth<= 1.1.0
Unauthenticated Arbitrary File Upload via 'export' AJAX Action vulnerability
10
22 hours ago