The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,478
Mitigations16,359
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@ooples/token-optimizer-mcp< 5.1.0
NPM: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
5.3
16 minutes ago
@ooples/token-optimizer-mcp< 5.1.0
NPM: Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
8.4
18 minutes ago
@budibase/server< 3.41.3
Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
7.1
2 hours ago
Epeken All Kurir<= 2.1.2
Unauthenticated Order Payment Confirmation Forgery vulnerability
3.7
12 hours ago
Paymob for WooCommerce< 4.1.9
Unauthenticated SQL Injection via Paymob Callback Pixel Lookup vulnerability
9.3
12 hours ago
WishList Member X<= 3.34.1
Unauthenticated Account Takeover via 'mergewith' Parameter vulnerability
9.8
12 hours ago
Embed Google Photos album<= 2.2.1
Contributor+ Stored XSS via link Shortcode Attribute vulnerability
6.5
12 hours ago
Bit Form<= 3.2.0
Authenticated (Administrator+) SQL Injection via 'filterText' Parameter vulnerability
7.6
12 hours ago
affiliate-toolkit<= 3.8.8
Authenticated (Administrator+) SQL Injection via 'orderby' Parameter vulnerability
7.6
12 hours ago
Astro Booking Engine<= 1.4.0
Cross-Site Request Forgery to Settings Reset vulnerability
5.4
12 hours ago
W3 Total Cache<= 2.10.3
Unauthenticated Stored Cross-Site Scripting via Comment Author Name vulnerability
7.1
12 hours ago
KiviCare< 4.5.2
Unauthenticated Privilege Escalation via Registration vulnerability
9.8
13 hours ago
Ecwid Shopping Cart< 7.0.9
Subscriber+ Store Disconnection via 'ec_disconnect' Action vulnerability
5.4
13 hours ago
Email Verification for WooCommerce< 3.2.6
Unauthenticated Account Takeover via Type-Juggling Authentication Bypass vulnerability
9.8
13 hours ago
ShopEngine< 4.9.3
Customer PII Disclosure via Forced Authentication vulnerability
5.4
13 hours ago
Amelia< 2.4.6
Provider+ Cross-Customer Appointment Data Disclosure via IDOR vulnerability
4.3
13 hours ago
WP Helper Premium< 4.7.6
Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation vulnerability
5.3
13 hours ago
Food Menu – Restaurant Menu & Online Ordering for WooCommerce< 6.0.2
Unauthenticated Reservation Status Modification vulnerability
5.3
13 hours ago
PPWP<= 1.9.21
WordPress PPWP - Password Protect Pages plugin <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
13 hours ago
FluentForm<= 6.2.11
Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values vulnerability
7.1
13 hours ago