Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,014
Mitigations
Mitigation rules
16,983
No official patch
13,348
In triage
1,212
Published soon
12
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
bbPress
<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
24/09/2026
omniroute
<= 3.8.50
NPM: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
9.5
32 minutes ago
n8n
< 2.37.7
NPM: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
5.9
32 minutes ago
n8n
< 2.37.7
NPM: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
5.9
35 minutes ago
n8n
< 1.123.76
NPM: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
5.3
37 minutes ago
n8n
< 2.37.7
NPM: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
5.1
41 minutes ago
n8n
< 1.123.76
NPM: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
5.9
46 minutes ago
n8n
< 1.123.76
NPM: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
6
47 minutes ago
n8n
< 1.123.76
NPM: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
6.3
47 minutes ago
n8n
< 1.123.76
NPM: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
6.3
48 minutes ago
n8n
< 2.37.7
NPM: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
6
49 minutes ago
n8n
< 1.123.76
NPM: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
5.3
53 minutes ago
Masteriyo - LMS
<= 3.4.0
WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
5.3
1 hour ago
RTMKit
<= 2.1.5
Cross Site Request Forgery (CSRF) vulnerability
5.4
1 hour ago
Starter Templates
<= 4.7.5
Insecure Direct Object References (IDOR) vulnerability
4.3
1 hour ago
Flexible Quantity – Measurement Price Calculator for WooCommerce
<= 2.3.21
Broken Access Control vulnerability
5.3
1 hour ago
Booktics
<= 1.0.24
Broken Access Control vulnerability
5.3
1 hour ago
Visual Composer Website Builder
<= 45.16.1
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
Site Kit by Google
<= 1.186.0
Cross Site Request Forgery (CSRF) vulnerability
4.3
1 hour ago
Quiz And Survey Master
<= 11.2.5
Insecure Direct Object References (IDOR) vulnerability
5.3
1 hour ago
Load more