Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,953
Mitigations
Mitigation rules
16,598
No official patch
13,325
In triage
1,076
Published soon
33
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
unleash-server
< 8.0.3
NPM: Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
4.1
31 minutes ago
unleash-server
< 7.5.2
NPM: Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
5.5
31 minutes ago
unleash-server
< 7.5.2
NPM: Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
7.5
32 minutes ago
Wawp
<= 4.8.6
Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure vulnerability
9.8
9 hours ago
WPForms Pro
<= 2.0.0.2
Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values vulnerability
7.1
9 hours ago
JSON Options
<= 0.0.4
Unauthenticated Arbitrary Options Update vulnerability
9.8
9 hours ago
Depicter Slider
< 4.8.0
Editor+ Arbitrary File Upload via ZIP Import vulnerability
9.1
9 hours ago
Kirki
< 6.2.3
Editor+ Stored XSS via Font Zip Upload vulnerability
6.5
9 hours ago
GutenKit
<= 2.4.15
Contributor+ Mailchimp Audience Data Disclosure vulnerability
4.3
9 hours ago
Admin and Site Enhancements (ASE)
< 9.0.1
Author+ Stored XSS via SVG Upload over XML-RPC vulnerability
5.9
9 hours ago
GutenKit
< 2.5.0
Author+ Stored XSS via SVG Upload vulnerability
5.9
9 hours ago
Royal Elementor Addons
< 1.7.1066
Admin+ Remote Code Execution via Widget Builder vulnerability
7.2
10 hours ago
SG AI Studio
<= 1.2.7
Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint vulnerability
4.3
10 hours ago
Events Made Easy
<= 3.2.5
Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property vulnerability
7.5
10 hours ago
Membership For WooCommerce
< 3.1.2
Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass vulnerability
5.3
10 hours ago
WPS Bidouille
< 1.33.5
Subscriber+ User Email Disclosure via wps_get_users vulnerability
5.3
10 hours ago
KiviCare
< 4.5.4
Patient+ Arbitrary Media Attachment Read via IDOR vulnerability
4.3
10 hours ago
KiviCare
< 4.5.4
Patient+ Cross-Patient Appointment Modification via IDOR vulnerability
4.3
10 hours ago
Easy Appointments
< 4.0.1
Contributor+ Sensitive Information Disclosure via REST Appointments Listing vulnerability
4.3
10 hours ago
Broken Link Checker
< 2.4.12
Unauthenticated RCE via Query Variable Injection vulnerability
10
10 hours ago
Load more