The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total48,582
Mitigations15,644
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WP Meta SEO<= 4.5.18
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
50 minutes ago
URL Preview<= 1.0
Unauthenticated Server-Side Request Forgery vulnerability
7.2
54 minutes ago
Kargo Takip<= 1.2
Unauthenticated Server-Side Request Forgery vulnerability
7.2
58 minutes ago
EntreDroppers<= 1.1.2
Reflected Cross-Site Scripting vulnerability
7.1
1 hour ago
Image Sizes on Demand<= 1.3
Reflected Cross-Site Scripting vulnerability
7.1
1 hour ago
Post Video Players<= 1.163
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Email JavaScript Cloak<= 1.03
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
ARForms<= 7.1.3
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
AdRotate Banner Manager<= 5.17.7
Authenticated (Contributor+) PHP Code Injection vulnerability
8.8
2 hours ago
ProfileGrid <= 5.9.9.2
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
2 hours ago
Welcome Software Publishing<= 0.0.31
Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation vulnerability
8.8
5 hours ago
WP Forms Connector<= 1.8
Missing Authorization to Unauthenticated Information Exposure vulnerability
7.5
5 hours ago
WP Forms Connector<= 1.8
Unauthenticated SQL Injection vulnerability
9.3
6 hours ago
Invoice Generator<= 1.0.0
Unauthenticated Account Takeover vulnerability
9.8
6 hours ago
SignUp & SignIn<= 1.0.0
Unauthenticated Privilege Escalation vulnerability
9.8
6 hours ago
Funnel Builder by FunnelKit<= 3.15.0.5
SQL Injection vulnerability
7.6
7 hours ago
WP Meta SEO<= 4.5.18
Authenticated (Contributor+) Server-Side Request Forgery vulnerability
6.4
21 hours ago
WP Latest Posts<= 5.0.11
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
21 hours ago
MIR blocks and shortcodes<= 1.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
21 hours ago
Advanced Contact Form 7 – Compact DB<= 1.0.0
Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion vulnerability
5.3
21 hours ago