Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,451
Mitigations
Mitigation rules
16,340
No official patch
13,251
In triage
1,150
Published soon
43
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
W3 Total Cache
<= 2.10.3
Unauthenticated Stored Cross-Site Scripting via Comment Author Name vulnerability
7.1
2 minutes ago
KiviCare
< 4.5.2
Unauthenticated Privilege Escalation via Registration vulnerability
9.8
39 minutes ago
Ecwid Shopping Cart
< 7.0.9
Subscriber+ Store Disconnection via 'ec_disconnect' Action vulnerability
5.4
45 minutes ago
Email Verification for WooCommerce
< 3.2.6
Unauthenticated Account Takeover via Type-Juggling Authentication Bypass vulnerability
9.8
47 minutes ago
ShopEngine
< 4.9.3
Customer PII Disclosure via Forced Authentication vulnerability
5.4
48 minutes ago
Amelia
< 2.4.6
Provider+ Cross-Customer Appointment Data Disclosure via IDOR vulnerability
4.3
49 minutes ago
WP Helper Premium
< 4.7.6
Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation vulnerability
5.3
50 minutes ago
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
< 6.0.2
Unauthenticated Reservation Status Modification vulnerability
5.3
58 minutes ago
PPWP
<= 1.9.21
WordPress PPWP - Password Protect Pages plugin <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
59 minutes ago
FluentForm
<= 6.2.11
Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values vulnerability
7.1
59 minutes ago
Prevent Direct Access
<= 2.8.8.8
WordPress Prevent Direct Access - Protect WordPress Files plugin <= 2.8.8.8 - Unauthenticated Protected File Access vulnerability
5.3
1 hour ago
Quick Paypal Payments
<= 5.7.50
Unauthenticated Payment Bypass via PayPal IPN vulnerability
5.3
1 hour ago
Payment Button for PayPal
<= 1.2.3.44
Unauthenticated Payment Price Manipulation vulnerability
5.3
1 hour ago
Payment Gateway for PayPal on WooCommerce
< 9.2.1
Unauthenticated Payment Bypass via PayPal Advanced Return Handler vulnerability
5.3
1 hour ago
Welcart e-Commerce
< 2.11.33
Unauthenticated Payment Bypass via Forged Settlement Callback vulnerability
5.3
1 hour ago
Wallet System for WooCommerce
< 2.7.10
Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount vulnerability
4.3
1 hour ago
Royal Elementor Addons
< 1.7.1065
Contributor+ Stored XSS via Icon Box Widget vulnerability
6.5
1 hour ago
Order Sync with Zendesk for WooCommerce
< 2.2.3
Unauthenticated Customer Order Data Disclosure vulnerability
5.3
1 hour ago
ProSolution WP Client
< 2.0.9
Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls vulnerability
4.3
1 hour ago
WP Photo Album Plus
< 9.2.09.002
Subscriber+ Cross-Album File Upload via Missing Authorization vulnerability
4.3
1 hour ago
Load more