Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,906
Mitigations
Mitigation rules
16,945
No official patch
13,338
In triage
1,200
Published soon
27
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
<= 4.4.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 minute ago
PublishPress Capabilities
<= 2.50.0
Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant vulnerability
7.2
7 minutes ago
YITH WooCommerce Waitlist Premium
<= 3.35.0
Authenticated (Subscriber+) Privilege Escalation to Admin vulnerability
8.8
12 minutes ago
WP Plugin Bluehost
<= 4.19.0
Unauthenticated Authentication Bypass vulnerability
9.8
18 minutes ago
WP Plugin Web
<= 2.3.5
Unauthenticated Authentication Bypass vulnerability
9.8
18 minutes ago
WP Plugin Crazy Domains
<= 2.5.2
Unauthenticated Authentication Bypass vulnerability
9.8
19 minutes ago
WP Module Data
<= 2.9.7
Unauthenticated Authentication Bypass vulnerability
9.8
19 minutes ago
WP Plugin Hostgator
<= 3.2.0
Unauthenticated Authentication Bypass vulnerability
9.8
20 minutes ago
Next-Cart Store to WooCommerce Migration
<= 3.9.8
Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint vulnerability
8.1
25 minutes ago
n8n
< 2.37.7
NPM: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
5.3
9 hours ago
nodemailer
< 9.1.0
NPM: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
6.5
9 hours ago
nodemailer
< 9.1.0
NPM: Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
7.5
9 hours ago
nodemailer
>= 6.9.16, < 9.1.0
NPM: Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
6.5
9 hours ago
@typespec/openapi3
<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
9 hours ago
@typespec/compiler
<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
9 hours ago
multer
< 2.3.0
NPM: multer vulnerable to Denial of Service via crafted multipart field names
7.5
9 hours ago
multer
2.2.0
NPM: multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
7.5
9 hours ago
multer
< 2.3.0
NPM: multer vulnerable to file size limit bypass via async fileFilter race condition
3.7
9 hours ago
multer
< 2.3.0
NPM: multer vulnerable to Denial of Service via oversized array index in field names
7.5
9 hours ago
morgan
< 1.12.0
NPM: morgan vulnerable to Log Forging via unescaped Unicode line separators
5.3
9 hours ago
Load more