The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,679
Mitigations13,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
YITH WooCommerce Quick View<= 2.7.0
Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode vulnerability
6.5
4 minutes ago
Mavix Education<= 1.0
Missing Authorization to Authenticated (Subscriber+) 'Creativ Demo Importer' Plugin Activation vulnerability
4.3
10 minutes ago
Header Footer Script Adder<= 2.0.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
11 minutes ago
Emplibot<= 1.0.9
Authenticated (Admin+) Server-Side Request Forgery vulnerability
4.4
44 minutes ago
HT Slider For Elementor<= 1.7.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 hour ago
404 Solution<= 3.1.0
Authenticated (Admin+) SQL Injection via 'filterText' Parameter vulnerability
7.6
1 hour ago
Design Import/Export<= 2.2
Authenticated (Administrator+) SQL Injection via XML File Import vulnerability
7.6
1 hour ago
HAPPY<= 1.0.9
Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Reply vulnerability
5.4
1 hour ago
Custom Post Type UI<= 1.18.1
Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter vulnerability
5.9
1 hour ago
Employee Spotlight<= 5.1.3
Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification vulnerability
5.3
1 hour ago
Image Slider by Ays<= 2.7.0
Cross-Site Request Forgery to Arbitrary Slider Deletion vulnerability
4.3
1 hour ago
GenerateBlocks<= 2.1.2
Authenticated (Contributor+) Information Exposure via Metadata vulnerability
4.3
1 hour ago
WPGraphQL Smart Cache< 2.0.1
Unauthenticated Private Content Disclosure vulnerability
7.5
5 hours ago
WPMasterToolKit<= 2.13.0
Authenticated (Author+) Code Injection vulnerability
7.2
12 hours ago
Simple CSV Table<= 1.0.1
Directory Traversal to Authenticated (Contributor+) Arbitrary File Read vulnerability
6.5
14 hours ago
VikRentItems Flexible Rental Management System<= 1.2.0
Reflected Cross-Site Scripting via 'delto' Parameter vulnerability
7.1
14 hours ago
Fancy Product Designer<= 6.4.8
Unauthenticated Stored Cross-Site Scripting via SVG File Upload vulnerability
7.1
14 hours ago
Flow-Flow Social Stream3.0.0-4.7.5
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
6.5
15 hours ago
Campay Woocommerce Payment Gateway<= 1.2.2
Unauthenticated Payment Bypass vulnerability
5.4
15 hours ago
Funnel Builder by FunnelKit<= 3.13.1.5
Unauthenticated SQL Injection vulnerability
9.3
15 hours ago