Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,473
Mitigations
Mitigation rules
17,128
No official patch
13,364
In triage
1,376
Published soon
10
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@file-viewer/doc
<= 2.3.0
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
23 hours ago
msdoc-viewer
<= 0.2.1
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
23 hours ago
adm-zip
< 0.6.1
NPM: adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
7.5
23 hours ago
md-editor-v3
<= 6.5.3
NPM: md-editor-v3: XSS via fenced-code language rendering bypass
6.1
23 hours ago
WP Magnific Popup
<= 1.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
Form Builder CP
< 1.2.47
Editor+ Stored XSS via form_structure vulnerability
6.5
1 day ago
KeepInMind Dashboard Notes
< 0.8.4.2
WordPress KeepInMind - Dashboard Notes plugin < 0.8.4.2 - Contributor+ Stored XSS vulnerability
6.5
1 day ago
Secure Copy Content Protection and Content Locking
< 5.1.5
Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter vulnerability
5.9
1 day ago
Store Locator WordPress
< 1.6.9
Admin+ Stored XSS via logo_name vulnerability
5.9
1 day ago
Shariff
<= 1.0.11
Admin+ Stored Cross-Site Scripting vulnerability
5.9
1 day ago
Bricksforge
< 3.1.8.8
Unauthenticated Arbitrary Password Reset via Pro Forms vulnerability
8.1
1 day ago
WP Photo Album Plus
<= 9.2.09.002
Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection vulnerability
7.5
1 day ago
Gravity Forms
<= 3.1.0.4
Unauthenticated Arbitrary File Upload via Hidden File Upload Field vulnerability
10
1 day ago
Forminator
<= 1.57.2
Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter vulnerability
9.1
1 day ago
WP Recipe Maker
<= 10.8.1
Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content vulnerability
9.1
1 day ago
WP2Social Auto Publish
<= 2.4.12
Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter vulnerability
5.9
1 day ago
Hotel Booking Lite
< 6.2.3
Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint vulnerability
5.3
1 day ago
SEO Booster
<= 7.4.7
Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() vulnerability
4.3
1 day ago
Save as PDF
<= 4.6.1
Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute vulnerability
8.8
1 day ago
Tutor LMS
<= 4.0.8
Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter vulnerability
5.3
1 day ago
Load more