The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,473
Mitigations17,128
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@file-viewer/doc<= 2.3.0
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
2 hours ago
msdoc-viewer<= 0.2.1
NPM: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
8.2
2 hours ago
adm-zip< 0.6.1
NPM: adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
7.5
2 hours ago
md-editor-v3<= 6.5.3
NPM: md-editor-v3: XSS via fenced-code language rendering bypass
6.1
2 hours ago
WP Magnific Popup<= 1.0
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
3 hours ago
Form Builder CP< 1.2.47
Editor+ Stored XSS via form_structure vulnerability
6.5
3 hours ago
KeepInMind Dashboard Notes< 0.8.4.2
WordPress KeepInMind - Dashboard Notes plugin < 0.8.4.2 - Contributor+ Stored XSS vulnerability
6.5
3 hours ago
Secure Copy Content Protection and Content Locking< 5.1.5
Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter vulnerability
5.9
3 hours ago
Store Locator WordPress< 1.6.9
Admin+ Stored XSS via logo_name vulnerability
5.9
3 hours ago
Shariff<= 1.0.11
Admin+ Stored Cross-Site Scripting vulnerability
5.9
3 hours ago
Bricksforge< 3.1.8.8
Unauthenticated Arbitrary Password Reset via Pro Forms vulnerability
8.1
4 hours ago
WP Photo Album Plus<= 9.2.09.002
Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection vulnerability
7.5
5 hours ago
Gravity Forms<= 3.1.0.4
Unauthenticated Arbitrary File Upload via Hidden File Upload Field vulnerability
10
5 hours ago
Forminator<= 1.57.2
Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter vulnerability
9.1
5 hours ago
WP Recipe Maker<= 10.8.1
Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content vulnerability
9.1
5 hours ago
WP2Social Auto Publish<= 2.4.12
Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter vulnerability
5.9
5 hours ago
Hotel Booking Lite< 6.2.3
Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint vulnerability
5.3
5 hours ago
SEO Booster<= 7.4.7
Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() vulnerability
4.3
5 hours ago
Save as PDF<= 4.6.1
Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute vulnerability
8.8
5 hours ago
Tutor LMS<= 4.0.8
Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter vulnerability
5.3
5 hours ago