Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,351
Mitigations
Mitigation rules
16,737
No official patch
13,321
In triage
1,062
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Forminator
< 1.57.1
Unauthenticated Multisite Site Creation and Privilege Escalation vulnerability
9.8
6 minutes ago
Everest Forms
<= 3.4.4
Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' vulnerability
7.2
15 minutes ago
Shared Files Pro
< 1.7.68
Unauthenticated Arbitrary File Deletion vulnerability
8.6
33 minutes ago
Shared Files
< 1.7.67
Unauthenticated Arbitrary File Deletion vulnerability
8.6
33 minutes ago
WP User Frontend
< 4.3.10
Editor+ PHP Object Injection vulnerability
7.2
34 minutes ago
Ultimate Member
2.6.7-2.12.1
Unauthenticated Privilege Escalation vulnerability
8.1
36 minutes ago
WP Rocket
<= 3.21.0.1
Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint vulnerability
7.1
37 minutes ago
WP Rocket
3.23.1-3.23.3.2
Unauthenticated Sensitive Data Exposure vulnerability
7.5
38 minutes ago
User Registration
< 5.2.6
Authenticated Privilege Escalation vulnerability
7.2
1 hour ago
WPBulky
<= 1.2.2
SQL Injection vulnerability
8.5
1 hour ago
Forminator
<= 1.57.1
Other vulnerability Type vulnerability
5.3
1 hour ago
Shared Files
< 1.7.67
Unauthenticated Limited File Upload vulnerability
5.3
1 hour ago
Shared Files Pro
< 1.7.70
Unauthenticated Limited File Upload vulnerability
5.3
1 hour ago
GiveWP
<= 4.16.7.1
Remote Code Execution (RCE) vulnerability
10
2 hours ago
Amelia
<= 2.2
Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission vulnerability
7.1
4 hours ago
wpForo Forum
<= 2.4.17
Unauthenticated SQL Injection via 'referer' Parameter vulnerability
9.3
4 hours ago
ElementsKit Pro
<= 4.10.1
Unauthenticated Stored Cross-Site Scripting via 's' Parameter vulnerability
7.1
4 hours ago
Tutor LMS
<= 4.0.5
Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters vulnerability
6.5
4 hours ago
One User Avatar
<= 2.5.4
Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter vulnerability
6.5
4 hours ago
LiteSpeed Cache
<= 7.8.1
Unauthenticated Stored Cross-Site Scripting via Comment Content vulnerability
7.1
5 hours ago
Load more