The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total36,785
Mitigations13,557
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
PAYGENT for WooCommerce<= 2.4.6
Missing Authorization to Unauthenticated Payment Callback Manipulation vulnerability
5.3
1 day ago
Integrate Dynamics 365 CRM<= 1.1.1
Authenticated (Administrator+) Stored Cross-Site Scripting via Field Mapping Configuration vulnerability
5.9
1 day ago
Advanced Ads<= 2.0.15
WordPress Advanced Ads - Ad Manager & AdSense plugin <= 2.0.15 - Authenticated (Admin+) SQL Injection vulnerability
7.6
1 day ago
Spin Wheel<= 2.1.0
Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter vulnerability
5.3
1 day ago
CM Email Registration Blacklist and Whitelist<= 1.6.2
Authenticated (Administrator+) Stored Cross-Site Scripting via 'black_email' Parameter vulnerability
5.9
1 day ago
Team Section Block<= 2.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link vulnerability
6.5
1 day ago
Community Events<= 1.5.6
Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter vulnerability
5.3
1 day ago
Phrase TMS Integration for WordPress<= 4.7.5
Missing Authorization to Authenticated (Subscriber+) Log Deletion vulnerability
5.4
1 day ago
User Registration Using Contact Form 7<= 2.5
Authenticated (Subscriber+) Information Exposure vulnerability
5.3
1 day ago
Church Admin<= 5.0.28
Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audio_url' Parameter vulnerability
4.4
1 day ago
RepairBuddy<= 4.1116
Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders vulnerability
5.3
1 day ago
Filr<= 1.2.11
WordPress Filr - Secure document library plugin <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload vulnerability
5.9
1 day ago
Modular DS2.5.2
Privilege Escalation vulnerability
10
1 day ago
Peach Payments Gateway<= 3.3.6
Broken Access Control vulnerability
6.5
2 days ago
The Aisle< 2.9.1
Local File Inclusion vulnerability
8.1
2 days ago
Powerlift< 3.2.1
Local File Inclusion vulnerability
8.1
2 days ago
bidorbuy Store Integrator<= 2.12.0
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
WP Mail<= 1.3
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Dooodl<= 2.3.0
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Syntax Highlighter Compress<= 3.0.83.3
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago