The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,558
Mitigations17,141
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WP Travel Engine<= 6.8.0
Authenticated (Contributor+) Local File Inclusion vulnerability
7.5
9 hours ago
PixelPlay<= 1.0.2
Missing Authorization to Unauthenticated Arbitrary API Key Deletion vulnerability
5.3
9 hours ago
Image Buzz<= 1.0.3
Missing Authorization to Unauthenticated Arbitrary API Key Modification vulnerability
5.3
9 hours ago
Page Builder: Live Composer<= 2.1.21
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
9 hours ago
Hostel<= 1.1.8
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
9 hours ago
wpForo Forum<= 3.1.5
Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover vulnerability
4.3
9 hours ago
Tutor LMS<= 4.0.7
Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion vulnerability
4.3
10 hours ago
Custom Field Template<= 2.7.8
Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion vulnerability
4.3
10 hours ago
Ultimate Addons for Contact Form 73.2.4-3.5.50
Unauthenticated Arbitrary File Upload vulnerability
10
11 hours ago
Botiga Pro< 1.6.5
Unauthenticated Arbitrary Blog Options Update vulnerability
9.8
11 hours ago
Contextual Related Posts<= 4.4.1
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago
Meta Box Frontend Submission<= 4.5.6
Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter vulnerability
9.8
12 hours ago
Meta Box AIO<= 3.11.0
Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter vulnerability
9.8
12 hours ago
Meta Box User Profile<= 3.11.0
Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter vulnerability
9.8
12 hours ago
Ultimate Post Kit<= 4.2.0
Cross-Site Scripting vulnerability
5.8
17 hours ago
APCu Manager< 4.5.0
Unauthenticated Stored XSS via Cache Key Pollution vulnerability
7.1
17 hours ago
User Submitted Posts< 20260608
Unauthenticated Stored XSS via Author Name vulnerability
7.1
17 hours ago
WP Support Plus Responsive Ticket System<= 9.1.2
Unauthenticated Stored XSS via File Upload vulnerability
7.1
18 hours ago
Ultimate Member< 2.12.0
Subscriber+ Stored XSS via Custom Textarea Profile Fields vulnerability
6.5
19 hours ago
Simple Membership< 4.7.5
Unauthenticated Stored XSS via Stripe Webhook API Version vulnerability
7.1
19 hours ago