Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,899
Mitigations
Mitigation rules
16,074
No official patch
13,135
In triage
1,196
Published soon
51
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
security-ninja-premium
< 5.290
Two-Factor Authentication Bypass vulnerability
7.5
1 hour ago
微信二维码登陆
<= 1.3
Unauthenticated Account Takeover vulnerability
9.8
1 hour ago
FacturaONE para WooCommerce con VeriFactu
< 5.37
Unauthenticated Remote Code Execution vulnerability
10
1 hour ago
Realtyna Organic IDX plugin
< 5.3.0
Unauthenticated Arbitrary File Upload to Remote Code Execution vulnerability
10
1 hour ago
Post Status Notifier Lite
< 1.13.0
Reflected XSS vulnerability
7.1
1 hour ago
Custom Fields Account Registration For Woocommerce
< 1.4
Unauthenticated Privilege Escalation vulnerability
9.8
1 hour ago
Advanced Responsive Video Embedder
10.8.7
Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter vulnerability
9.8
2 hours ago
MemberGlut
< 1.1.5
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
2 hours ago
Printcart Web to Print Product Designer for WooCommerce
< 2.5.3
Unauthenticated Arbitrary File Read and Server-Side Request Forgery vulnerability
8.6
2 hours ago
MainWP Child
< 6.1.2
Unauthenticated Administrator Authentication Bypass vulnerability
9.8
2 hours ago
style-dictionary
>= 4.3.0, < 5.4.4
Prototype Pollution in convertTokenData utility function
8.8
10 hours ago
@hypequery/clickhouse
< 2.0.2
NPM: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
9.8
10 hours ago
@nocobase/plugin-collection-sql
< 2.0.62
NPM: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
6.8
12 hours ago
qti-neon
1.0.0
NPM: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
8.6
16 hours ago
@novu/application-generic
< 3.17.0
NPM: @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
6.8
18 hours ago
@wakaru/cli
>= 1.0.0, < 1.4.0
NPM: @wakaru/cli arbitrary file write during bundle unpack
7.1
18 hours ago
Location Weather
<= 3.0.6
Cross Site Scripting (XSS) vulnerability
6.5
2 days ago
Photonic Gallery & Lightbox for Flickr, SmugMug & Others
<= 3.33
Cross Site Scripting (XSS) vulnerability
6.5
2 days ago
WP Google Review Slider
<= 18.4
SQL Injection vulnerability
7.6
2 days ago
WP Google Review Slider
<= 18.4
Cross Site Request Forgery (CSRF) vulnerability
4.3
2 days ago
Load more