The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total36,716
Mitigations13,522
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
List Site Contributors<= 1.1.8
Reflected Cross-Site Scripting via alpha vulnerability
7.1
35 minutes ago
AJS Footnotes<= 1.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
39 minutes ago
Name Directory<= 1.30.3
Unauthenticated Stored Cross-Site Scripting via Multiple Parameters vulnerability
7.1
47 minutes ago
GeekyBot<= 1.1.7
WordPress GeekyBot - Generate AI Content Without Prompt, Chatbot and Lead Generation plugin <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Gotham Block Extra Light<= 1.5.0
Authenticated (Contributor+) Arbitrary File Read via 'ghostban' Shortcode vulnerability
6.5
1 hour ago
Shipping Rate By Cities<= 2.0.0
Unauthenticated SQL Injection via 'city' Parameter vulnerability
9.3
1 hour ago
News and Blog Designer Bundle<= 1.1
Unauthenticated Local File Inclusion vulnerability
8.1
1 hour ago
Dreamer Blog<= 1.2
Subscriber+ Arbitrary Plugin Installation vulnerability
8.8
2 hours ago
Integration Opvius AI for WooCommerce<= 1.3.0
Unauthenticated Arbitrary File Deletion/Read via Path Traversal vulnerability
8.6
2 hours ago
Modular DS<= 2.5.1
Privilege Escalation vulnerability
10
6 hours ago
DASHBOARD BUILDER<= 1.5.7
Cross-Site Request Forgery to SQL Injection vulnerability
8.2
10 hours ago
WMF Mobile Redirector<= 1.2
Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters vulnerability
5.9
15 hours ago
Short Link<= 1.0
Authenticated (Administrator+) Stored Cross-Site Scripting via Administration Settings Page vulnerability
5.9
15 hours ago
Aplazo Payment Gateway<= 1.4.2
Missing Authorization to Unauthenticated Order Status Manipulation vulnerability
5.3
15 hours ago
PayHere Payment Gateway Plugin for WooCommerce<= 2.3.9
Missing Authorization to Unauthenticated Order Status Modification vulnerability
5.3
15 hours ago
Float Payment Gateway<= 1.1.9
Improper Authorization to Unauthenticated Order Status Manipulation vulnerability
5.3
15 hours ago
WP Allowed Hosts<= 1.0.8
Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed-hosts' Parameter vulnerability
5.9
15 hours ago
LinkedIn SC<= 1.1.9
Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page vulnerability
5.9
15 hours ago
Stopwords for comments<= 1.1
Missing Authorization to Cross-Site Request Forgery vulnerability
4.3
15 hours ago
SocialChamp with WordPress<= 1.3.3
Cross-Site Request Forgery to Plugin Settings Update vulnerability
4.3
15 hours ago