Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,173
Mitigations
Mitigation rules
17,868
No official patch
13,593
In triage
989
Published soon
109
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Before After Image Comparison – Image comparison for WP
<= 1.1.21
Broken Access Control vulnerability
5.4
42 minutes ago
WPFunnels
<= 3.13.3
Cross Site Scripting (XSS) vulnerability
6.5
52 minutes ago
All Bootstrap Blocks
<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
1 hour ago
Asgaros Forum
<= 3.4.0
Broken Access Control vulnerability
4.3
1 hour ago
Html5 Audio Player
<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
Restrict User Access – Membership Plugin with Force
<= 2.8.1
Broken Access Control vulnerability
5.3
1 hour ago
WP Event Manager
<= 3.4.1
Broken Access Control vulnerability
5.4
1 hour ago
Scripts n Styles
<= 3.5.8
Broken Access Control vulnerability
5.3
1 hour ago
AI Translation for Polylang
<= 1.6.2
Broken Access Control vulnerability
5.4
1 hour ago
JetBlocks For Elementor
<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Ocean Pro Demos
<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Ocean eComm Treasure Box
<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Redux Framework
<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
5 hours ago
fast-jwt
<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
14 hours ago
@adonisjs/http-server
<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
14 hours ago
fast-jwt
<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
14 hours ago
fast-jwt
>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
14 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
14 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
14 hours ago
fast-jwt
6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
14 hours ago
Load more