Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
39,639
Mitigations
Mitigation rules
14,804
No official patch
11,260
In triage
1,518
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
Loco Translate
<= 2.8.2
Reflected Cross-Site Scripting via 'update_href' Parameter vulnerability
7.1
1 hour ago
Oxygen
<= 6.0.8
Unauthenticated Server-Side Request Forgery via route_path vulnerability
7.2
1 hour ago
Gravity SMTP
<= 2.1.4
Unauthenticated Sensitive Information Exposure via REST API vulnerability
7.5
2 hours ago
Everest Forms Pro
<= 1.9.12
Unauthenticated Remote Code Execution via Calculation Field vulnerability
10
2 hours ago
Contact Form by Supsystic
<= 1.7.36
Unauthenticated Server-Side Template Injection via Prefill Functionality vulnerability
10
3 hours ago
Ibtana
<= 1.2.5.7
WordPress Ibtana - WordPress Website Builder plugin <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
9 hours ago
TrueBooker
<= 1.1.4
WordPress Truebooker - Appointment Booking and Scheduler Plugin plugin <= 1.1.4 - Sensitive Information Exposure via Views Files vulnerability
5.3
9 hours ago
Debugger & Troubleshooter
<= 1.3.2
Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation vulnerability
9.8
12 hours ago
Fluent Booking
<= 2.0.01
Unauthenticated Stored Cross-Site Scripting via Multiple Parameters vulnerability
7.1
20 hours ago
Ultimate Member
<= 2.11.2
Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag vulnerability
8
20 hours ago
Blackhole for Bad Bots
<= 3.8
Unauthenticated Stored Cross-Site Scripting via User-Agent HTTP Header vulnerability
7.1
20 hours ago
LeadConnector
< 3.0.22
Unauthenticated Rest Call vulnerability
6.5
21 hours ago
Shared Files
< 1.7.58
Contributor+ Arbitrary File Download vulnerability
6.5
21 hours ago
Frontend Admin by DynamiApps
<= 3.28.31
Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts vulnerability
7.2
22 hours ago
FloristPress
<= 7.8.2
Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability
7.1
1 day ago
JS Help Desk
<= 3.0.4
WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability
9.3
1 day ago
SureForms
<= 2.5.2
Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
7.5
1 day ago
Masteriyo - LMS
<= 2.1.6
Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability
8.8
1 day ago
Responsive Plus
< 3.4.3
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
1 day ago
WP Job Portal
<= 2.4.9
Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field vulnerability
8.8
1 day ago
Load more