The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total36,468
Mitigations13,396
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
EmailKit<= 1.6.1
Authenticated (Author+) Arbitrary File Read via Path Traversal vulnerability
6.5
3 minutes ago
User Activity Log<= 2.2
Unauthenticated Limited Options Update via Failed Login vulnerability
7.5
9 minutes ago
Latest Registered Users<= 1.4
Missing Authorization to Unauthenticated Sensitive Information Exposure via User Data Export vulnerability
7.5
25 minutes ago
Money Space<= 2.13.9
Unauthenticated Sensitive Information Exposure vulnerability
8.6
30 minutes ago
iPaymu Payment Gateway for WooCommerce<= 2.0.2
Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure vulnerability
8.2
47 minutes ago
Yoco Payments<= 3.8.8
Unauthenticated Arbitrary File Read vulnerability
7.5
59 minutes ago
Drag and Drop Multiple File Upload – Contact Form 7<= 1.3.9.2
WordPress Drag and Drop Multiple File Upload - Contact Form 7 plugin <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload vulnerability
10
1 hour ago
Optional Email<= 1.3.11
Unauthenticated Privilege Escalation to Account Takeover vulnerability
9.8
1 hour ago
Wish To Go<= 0.5.2
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
7 hours ago
Simcast<= 1.0.0
Cross-Site Request Forgery to Settings Update vulnerability
4.3
7 hours ago
AH Shortcodes<= 1.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'column' Shortcode Attribute vulnerability
6.5
7 hours ago
FluentForm<= 6.1.7
Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder vulnerability
5.4
7 hours ago
Snillrik Restaurant<= 2.2.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'menu_style' Shortcode Attribute vulnerability
6.5
7 hours ago
Email Customizer for WooCommerce<= 2.6.7
Authenticated (Administrator+) Stored Cross-Site Scripting via Email Template Content vulnerability
4.4
7 hours ago
Cool YT Player<= 1.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
7 hours ago
My Album Gallery<= 1.0.4
Authenticated (Author+) Stored Cross-Site Scripting via Image Title vulnerability
5.9
7 hours ago
My Album Gallery<= 1.0.4
Authenticated (Contributor+) Stored Cross-Site Scripting via 'style_css' Shortcode Attribute vulnerability
6.5
7 hours ago
AD Sliding FAQ<= 2.4
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
7 hours ago
Responsive Pricing Table<= 5.1.12
Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency' vulnerability
6.5
8 hours ago
Responsive Pricing Table<= 5.1.12
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
8 hours ago