The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,493
Mitigations16,840
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Simply Schedule Appointments<= 1.6.12.23
Cross Site Request Forgery (CSRF) vulnerability
8.8
6 minutes ago
Ultimate Gift Cards For WooCommerce<= 3.2.9
Broken Access Control vulnerability
5.3
8 minutes ago
Activity Log<= 2.13.1
Cross Site Request Forgery (CSRF) vulnerability
7.1
9 minutes ago
Broken Link Checker<= 2.4.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
FluentCart<= 1.6.2
Authenticated (Custom+) Arbitrary File Deletion vulnerability
7.7
3 hours ago
WP Project Manager Pro<= 4.0.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
3 hours ago
Måne<= 1.7
Unauthenticated Local File Inclusion vulnerability
8.1
3 hours ago
WordPress Persistent Login<= 3.1.0
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
3 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.4.1
Unauthenticated Arbitrary File Upload vulnerability
10
4 hours ago
TranslatePress<= 3.3.1
Unauthenticated Account Takeover vulnerability
9.8
4 hours ago
Formidable Charts<= 2.0.1
Unauthenticated Arbitrary File Read via 'frm_graph' Parameter vulnerability
7.5
4 hours ago
sanitize-html>= 1.9.0, <= 2.17.6
NPM: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
5.4
12 hours ago
nanoid< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
14 hours ago
pnpm>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
14 hours ago
Easy Waveform Player<= 1.2.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
pnpm>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
15 hours ago
@appium/base-driver<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
15 hours ago
Divi<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
16 hours ago
SigmaForms Pro – AI Generated Forms<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
17 hours ago
DevKit Pro<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
17 hours ago