The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,170
Mitigations16,181
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
TableOn<= 1.0.5.1
Unauthenticated Blind SQL Injection vulnerability
9.3
8 minutes ago
wiseCampaign<= 1.1.14
Missing Authorization to Unauthenticated Plugin Configuration Modification vulnerability
7.5
11 minutes ago
User Access Manager<= 2.3.12
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
24 minutes ago
Authora : Easy login with mobile number< 1.7.7
WordPress Authora : Easy login with mobile number plugin < 1.7.7 - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover vulnerability
9.8
26 minutes ago
Webinfos<= 1.2
Unauthenticated Arbitrary File Upload vulnerability
10
29 minutes ago
Login Social<= 1.0.4
Unauthenticated Account Takeover vulnerability
9.8
31 minutes ago
POUCO Import Users<= 1.0.0
Unauthenticated Privilege Escalation vulnerability
9.8
36 minutes ago
Lenxel WP<= 1.0.31
Unauthenticated Account Takeover vulnerability
9.8
38 minutes ago
Support Genix< 1.4.48
Unauthenticated Arbitrary File Read vulnerability
7.5
40 minutes ago
Bit File Manager6.0-6.9
WordPress File Manager plugin 6.0-6.9 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion vulnerability
8.6
43 minutes ago
WPMU DEV Dashboard<= 5.0.0
Authentication Bypass to Arbitrary plugin Installation (Remote Code Execution) vulnerability
8.1
45 minutes ago
Restrict Content<= 4.0.0
Unauthenticated Password Reset Link Poisoning to Account Takeover vulnerability
9.8
1 hour ago
FluentSMTP<= 2.2.95
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Popup by Supsystic<= 1.12.0
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
1 hour ago
nuxt>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
7.5
10 hours ago
nuxt>= 3.4.0, < 3.21.10
NPM: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
8.1
10 hours ago
@nuxt/devtools< 3.3.1
NPM: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
9.6
10 hours ago
nuxt>= 3.1.0, < 3.21.10
NPM: Nuxt: Unauthorized Component Instantiation via Server Island Props
4.8
10 hours ago
nuxt>= 4.4.0, <= 4.5.0
NPM: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
7.5
10 hours ago
nuxt>= 3.21.7, < 3.21.10
NPM: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
8.2
10 hours ago