Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,139
Mitigations
Mitigation rules
17,016
No official patch
13,374
In triage
1,234
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
BookIt
< 2.6.0.1
Unauthenticated Appointment PII Disclosure vulnerability
5.3
1 day ago
rtMedia for WordPress, BuddyPress and bbPress
< 4.7.12
Subscriber+ Arbitrary Activity Privacy Modification vulnerability
4.2
1 day ago
User Registration
< 5.2.8
Unauthenticated Open Redirect vulnerability
4.7
1 day ago
User Registration
5.0-5.2.7
Unauthenticated User Data Disclosure vulnerability
3.7
1 day ago
Rox Appointment Booking – Appointment Booking Scheduling Solution
1.0.9-1.2.2
Unauthenticated Customer PII Disclosure vulnerability
5.3
2 days ago
ChatBot
< 8.5.7
Unauthenticated AI Provider API Abuse vulnerability
5.3
2 days ago
Product XML Feed Manager for WooCommerce
< 3.1.1
Contributor+ Arbitrary Product Deletion vulnerability
4.9
2 days ago
Client Invoicing by Sprout Invoices
< 20.8.16
Subscriber+ Private Note Overwrite vulnerability
4.3
2 days ago
WP Highlight Box
<= 1.0
Contributor+ Stored XSS vulnerability
6.5
2 days ago
Masteriyo - LMS
< 3.4.1
Instructor+ Stored XSS vulnerability
6.5
2 days ago
BEAR
< 1.2.2
Taxonomy Term Modification vulnerability
4.3
2 days ago
BEAR
< 1.2.2
Meta Field Configuration Update vulnerability
4.3
2 days ago
Masteriyo - LMS
1.14.0-3.4.0
Instructor+ Arbitrary Post Disclosure vulnerability
2.7
2 days ago
BEAR
< 1.2.2
Authenticated Product Download URL and Meta Disclosure vulnerability
2.2
2 days ago
SureRank
1.6.2-1.10.0
Unauthenticated Author Email Disclosure vulnerability
5.3
2 days ago
Temporary Login Without Password
1.5-1.9.8
Multisite Subsite Admin+ Network Super Admin Privilege Escalation vulnerability
7.2
2 days ago
Custom Menu Wizard Widget
<= 3.3.1
Contributor+ Stored XSS vulnerability
6.5
2 days ago
yayson
<= 4.2.0
NPM: yayson: Prototype pollution in Store/LegacyStore deserialization
9.1
2 days ago
@mockoon/commons-server
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
2 days ago
@mockoon/cli
< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
2 days ago
Load more