Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
39,308
Mitigations
Mitigation rules
14,600
No official patch
11,211
In triage
1,323
Published soon
43
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear
Affected software | Vulnerability
Risk
Disclosed
Writeprint Stylometry
<= 0.1
Reflected Cross-Site Scripting via 'p' Parameter vulnerability
7.1
1 hour ago
[CR]Paid Link Manager
<= 0.5
Reflected Cross-Site Scripting vulnerability
7.1
1 hour ago
WP Go Maps
<= 10.0.05
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
6.5
2 hours ago
Duplicate Post
<= 4.5
Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability
5.4
6 hours ago
Subscriptions for WooCommerce
<= 1.9.2
Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability
5.3
6 hours ago
Royal Elementor Addons
<= 1.7.1049
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
5.3
6 hours ago
Booster for WooCommerce
< 7.11.3
Broken Access Control vulnerability
5.3
1 day ago
WowStore
<= 4.4.3
WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
9.3
1 day ago
NEX-Forms
<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id vulnerability
7.5
1 day ago
NEX-Forms
<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license vulnerability
4.3
1 day ago
WP User Frontend
<= 4.2.8
Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability
5.3
1 day ago
Wicked Folders
<= 4.1.0
Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion vulnerability
4.3
1 day ago
Thim Elementor Kit
<= 1.3.7
Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
5.3
1 day ago
WP EasyPay
<= 4.2.11
Broken Access Control vulnerability
5.4
1 day ago
Modern Events Calendar
<= 7.29.0
Broken Access Control vulnerability
5.3
1 day ago
Curly Core
<= 2.1.6
Local File Inclusion vulnerability
8.1
2 days ago
Organici Library
<= 2.1.2
SQL Injection vulnerability
8.5
2 days ago
Organici Library
<= 2.1.2
PHP Object Injection vulnerability
8.8
2 days ago
Organici Library
<= 2.1.2
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
CitiLights
<= 3.7.1
PHP Object Injection vulnerability
8.8
2 days ago
Load more