Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,351
Mitigations
Mitigation rules
16,739
No official patch
13,321
In triage
1,062
Published soon
8
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WP OAuth Server
< 6.3.1
Unauthenticated OAuth Token and User Data Disclosure vulnerability
7.5
6 minutes ago
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
< 2.1.2
Unauthenticated Arbitrary Price Manipulation vulnerability
7.5
7 minutes ago
Advanced File Manager
< 5.4.13
Authenticated Arbitrary File Read and Write via fma_load_fma_ui vulnerability
7.5
8 minutes ago
Firebase Authentication
< 1.7.1
Unauthenticated Account Takeover vulnerability
9.8
9 minutes ago
WPMU DEV Dashboard
<= 5.0.1
Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion vulnerability
9.8
10 minutes ago
Product Input Fields for WooCommerce
< 2.0.2
Unauthenticated Arbitrary File Upload vulnerability
10
16 minutes ago
Bit File Manager
< 6.9.1
Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch vulnerability
8.1
21 minutes ago
Forminator
< 1.57.1
Unauthenticated Multisite Site Creation and Privilege Escalation vulnerability
9.8
35 minutes ago
Everest Forms
<= 3.4.4
Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' vulnerability
7.2
45 minutes ago
Shared Files Pro
< 1.7.68
Unauthenticated Arbitrary File Deletion vulnerability
8.6
1 hour ago
Shared Files
< 1.7.67
Unauthenticated Arbitrary File Deletion vulnerability
8.6
1 hour ago
WP User Frontend
< 4.3.10
Editor+ PHP Object Injection vulnerability
7.2
1 hour ago
Ultimate Member
2.6.7-2.12.1
Unauthenticated Privilege Escalation vulnerability
8.1
1 hour ago
WP Rocket
<= 3.21.0.1
Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint vulnerability
7.1
1 hour ago
WP Rocket
3.23.1-3.23.3.2
Unauthenticated Sensitive Data Exposure vulnerability
7.5
1 hour ago
User Registration
< 5.2.6
Authenticated Privilege Escalation vulnerability
7.2
1 hour ago
WPBulky
<= 1.2.2
SQL Injection vulnerability
8.5
1 hour ago
Forminator
<= 1.57.1
Other vulnerability Type vulnerability
5.3
1 hour ago
Shared Files
< 1.7.67
Unauthenticated Limited File Upload vulnerability
5.3
1 hour ago
Shared Files Pro
< 1.7.70
Unauthenticated Limited File Upload vulnerability
5.3
1 hour ago
Load more