Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
38,599
Mitigations
Mitigation rules
14,146
No official patch
10,982
In triage
1,291
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
Simple Membership
<= 4.7.0
Unauthenticated Improper Handling of Missing Values vulnerability
6.5
4 hours ago
WP Customer Reviews
<= 3.7.5
Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter vulnerability
7.1
4 hours ago
Shield Security
<= 21.0.8
Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter vulnerability
7.1
6 hours ago
xmlrpc attacks blocker
<= 1.0
Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' vulnerability
7.1
7 hours ago
iXML
<= 0.6
WordPress iXML - Google XML sitemap generator plugin <= 0.6 - Reflected Cross-Site Scripting via 'iXML_email' Parameter vulnerability
7.1
7 hours ago
Easy Author Image
<= 1.7
Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Picture URL vulnerability
6.5
8 hours ago
Wholesale Suite
<= 2.2.1
Privilege Escalation vulnerability
7.2
2 days ago
Woocommerce Wholesale Lead Capture
<= 1.17.8
Privilege Escalation vulnerability
9.8
2 days ago
Woocommerce Wholesale Lead Capture
<= 1.17.8
Arbitrary File Upload vulnerability
9
2 days ago
EventPrime
<= 4.2.8.3
Sensitive Data Exposure vulnerability
5.3
3 days ago
Smartsupp – live chat, chatbots, AI and lead generation
<= 3.9.1
WordPress Smartsupp - live chat, AI shopping assistant and chatbots plugin <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
3 days ago
WooCommerce Checkout Manager
<= 7.8.1
Unauthenticated Limited File Upload vulnerability
5.3
3 days ago
Aruba HiSpeed Cache
<= 3.0.2
Missing Authorization to Unauthenticated Plugin's Settings Modification vulnerability
6.5
3 days ago
Ads Pro
<= 5.0
Broken Access Control vulnerability
5.4
3 days ago
Aruba HiSpeed Cache
<= 3.0.2
Reflected Cross-Site Scripting vulnerability
7.1
3 days ago
Ultimate Member
<= 2.11.1
Reflected Cross-Site Scripting via Filter Parameters vulnerability
7.1
3 days ago
Image Optimizer by Elementor
<= 1.7.1
Broken Access Control vulnerability
4.3
3 days ago
wpForo Forum
<= 2.4.14
Unauthenticated Time-Based SQL Injection vulnerability
9.3
3 days ago
WooCommerce Product Table Lite
<= 4.6.2
Unauthenticated Time-Based SQL Injection via 'search' Parameter vulnerability
9.3
3 days ago
Master Addons for Elementor
<= 2.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' vulnerability
6.5
3 days ago
Load more