Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,924
Mitigations
Mitigation rules
16,592
No official patch
13,325
In triage
1,068
Published soon
73
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
JetEngine
< 3.8.14
Author+ Stored XSS via SVG Upload vulnerability
5.9
4 minutes ago
WP Directory Kit
< 1.5.7
Unauthenticated User Email Disclosure via select_2_ajax_user vulnerability
5.3
4 minutes ago
W3 Total Cache
< 2.10.5
Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key vulnerability
9.8
42 minutes ago
TabaPay Gateway
<= 1.4.0
Unauthenticated Account Takeover via Payment Callback vulnerability
9.8
57 minutes ago
Product Shortlist
<= 1.0.4
Unauthenticated SQL Injection via get_shortlisted_products vulnerability
9.3
1 hour ago
SmartCrawl
< 3.16.3
Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration vulnerability
4.3
1 hour ago
Simple File List
<= 6.3.11
Unauthenticated Stored XSS via File Description vulnerability
7.1
1 hour ago
Simple File List
<= 6.3.11
Unauthenticated Arbitrary File Read and Move via Path Traversal vulnerability
7.5
1 hour ago
User Verification
<= 2.0.47
Unauthenticated Arbitrary Account Lockout via IDOR vulnerability
7.5
1 hour ago
Easy Media Replace
<= 0.2.0
Author+ Stored XSS via Attachment Title vulnerability
5.9
1 hour ago
YayCurrency
< 3.3.5
Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration vulnerability
5.3
1 hour ago
Quiz And Survey Master
< 11.2.4
Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR vulnerability
4.3
1 hour ago
Quiz And Survey Master
< 11.2.4
Contributor+ Arbitrary Quiz Text Settings Update via IDOR vulnerability
4.3
1 hour ago
Booking calendar, Appointment Booking System
<= 3.2.36
Unauthenticated Stored XSS via SVG File Upload vulnerability
7.1
1 hour ago
10Web Booster – Website speed optimization, Cache & Page Speed optimizer
< 2.33.5
Unauthenticated Stored XSS via Critical CSS Token Bypass vulnerability
4.7
1 hour ago
WCFM Marketplace
< 3.8.1
Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR vulnerability
4.3
1 hour ago
Dinatur
<= 1.18
Unauthenticated SQL Injection via Column Name Injection vulnerability
9.3
1 hour ago
WP Event SOlution
< 4.1.21
Contributor+ Schedule Deletion and Modification via IDOR vulnerability
4.3
1 hour ago
WP Event SOlution
< 4.1.21
Contributor+ User Role and Meta Modification via Speaker Creation vulnerability
4.3
1 hour ago
WP Event SOlution
< 4.1.21
Contributor+ Speaker Account Deletion via IDOR vulnerability
4.3
1 hour ago
Load more