Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,532
Mitigations
Mitigation rules
16,392
No official patch
13,264
In triage
1,147
Published soon
13
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Forminator
<= 1.56.1
Unauth. Arbitrary File Upload
9.8
36 minutes ago
ep_etherpad-lite
<= 1.8.14
NPM: Etherpad has stored XSS in HTML export via unescaped attribute-pool values
8.7
1 hour ago
ep_etherpad-lite
<= 1.8.14
NPM: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
0
1 hour ago
vm2
<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
1 hour ago
vm2
<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
1 hour ago
vm2
<= 3.11.5
NPM: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
9.8
1 hour ago
vm2
<= 3.11.5
NPM: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
9.9
1 hour ago
vm2
<= 3.11.5
NPM: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
8.7
1 hour ago
Gravity Booster – Styles & Layouts for Gravity Forms
<= 6.0
Broken Access Control vulnerability
5.4
1 hour ago
RomethemeForm For Elementor
<= 1.2.6
Broken Access Control vulnerability
4.3
1 hour ago
WP Table Builder
<= 2.2.0
Broken Access Control vulnerability
4.3
1 hour ago
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery
<= 1.16.20
Sensitive Data Exposure vulnerability
5.3
1 hour ago
Shortcodes and extra features for Phlox theme
<= 2.17.22
Sensitive Data Exposure vulnerability
5.3
1 hour ago
Razorpay for WooCommerce
<= 4.8.7
Insecure Direct Object References (IDOR) vulnerability
5.3
1 hour ago
@medplum/core
<= 5.1.5
NPM: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
7.1
5 hours ago
deepmerge-ts
< 8.0.0
NPM: DeepmergeTS has stack exhaustion when merging recursive object graphs
8.2
5 hours ago
TrueBooker
<= 1.2.6
Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter vulnerability
9.8
6 hours ago
Wholesale Market
<= 2.2.2
Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter vulnerability
8.8
7 hours ago
KiviCare
<= 4.5.1
Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter vulnerability
8.5
7 hours ago
Groundhogg
<= 4.5.14
Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter vulnerability
8.5
7 hours ago
Load more