The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,094
Mitigations16,101
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Streamit<= 4.5.0
Unauthenticated Remote Code Execution vulnerability
10
15 minutes ago
WP Media folder Addon<= 4.1.6
Unauthenticated Arbitrary File Download vulnerability
7.5
37 minutes ago
Extra Checkout Options - addon for Extra Product Options plugin<= 2.3.2
WordPress Extra Checkout Options - addon for Extra Product Options plugin plugin <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings vulnerability
8.8
1 hour ago
Cost Calculator Builder Pro<= 4.0.3
Unauthenticated Remote Code Execution vulnerability
10
1 hour ago
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light<= 2.4.37
Missing Authorization to Unauthenticated Privilege Escalation vulnerability
9.8
1 hour ago
MountDev AI MCP Connector for WordPress<= 1.6.1
Unauthenticated Privilege Escalation vulnerability
9.8
1 hour ago
SAML SP Single Sign On<= 5.4.4
Unauthenticated Authentication Bypass vulnerability
9.8
2 hours ago
WPForms Pro<= 1.10.1.1
Unauthenticated Arbitrary File Write vulnerability
9
2 hours ago
EventON Action User<= 2.5.14
Missing Authorization to Unauthenticated Privilege Escalation vulnerability
7.3
2 hours ago
SMS Alert Order Notifications<= 3.9.7
Unauthenticated Authentication Bypass to Account Takeover vulnerability
9.8
2 hours ago
WP Password Policy<= 3.7.1
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
Eazy Plugin Manager<= 4.4.1
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
2 hours ago
TrueBooker< 1.2.4
Unauthenticated Account Takeover vulnerability
9.8
2 hours ago
BookingPress Appointment Booking Pro< 5.7.3
Unauthenticated Customer PII Disclosure and Booking Tampering vulnerability
8.2
3 hours ago
Subscriptions for WooCommerce<= 2.0.0
Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation vulnerability
7.2
11 hours ago
mathlive<= 0.109.2
NPM: mathlive's Lack of Escaping of HTML allows for XSS
6.3
16 hours ago
@aws/agentcore>= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0
NPM: AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
9
17 hours ago
@dynatrace-oss/dynatrace-mcp-server< 1.8.7
NPM: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
3.7
18 hours ago
Improved Save Button<= 1.2.1
Authenticated (Author+) Second-Order SQL Injection vulnerability
8.5
19 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
8.3
19 hours ago