Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,109
Mitigations
Mitigation rules
17,346
No official patch
13,360
In triage
1,356
Published soon
45
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
axios
>= 1.7.0, < 1.20.0
NPM: Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
6.9
17 minutes ago
axios
>= 0.27.2, < 0.34.0
NPM: Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
6.9
17 minutes ago
axios
>= 1.16.1, < 1.20.0
NPM: Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
8.2
27 minutes ago
axios
>= 1.15.0, < 1.20.0
NPM: Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
8.2
27 minutes ago
axios
>= 0.28.0, < 0.34.0
NPM: Axios: Prototype Pollution Gadget in axios toFormData Options
8.3
27 minutes ago
axios
>= 1.13.0, < 1.20.0
NPM: Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
7
28 minutes ago
axios
>= 1.13.0, < 1.20.0
NPM: Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
8.2
29 minutes ago
next
>= 16.2.0, < 16.3.6
NPM: Next.js: Remote Code Execution in next/og ImageResponse
9.5
42 minutes ago
@nestjs/microservices
< 11.2.5
NPM: Nest: Unbounded memory growth in the NestJS TCP microservice transport
6.5
46 minutes ago
EWWW Image Optimizer
8.6.0-8.7.7
WordPress EWWW Image Optimizer plugin 8.6.0 - 8.7.7 - Author+ PHP Object Injection vulnerability
6.6
47 minutes ago
WP User Frontend
2.5.8-4.3.11
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
47 minutes ago
FluentCart
< 1.6.5
Unauthenticated Guest Customer Account Takeover vulnerability
6.5
47 minutes ago
Solace Extra
< 1.7.2
Unauthenticated Non-Published Post Content Disclosure vulnerability
7.5
48 minutes ago
@nestjs/platform-fastify
< 11.2.4
NPM: @nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
7.4
48 minutes ago
nodemailer
>= 9.1.0, <= 10.0.4
NPM: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
7.5
49 minutes ago
Newsletter
<= 9.3.9
Unauthenticated Insufficiently Protected Credentials vulnerability
5.3
1 hour ago
Premium Addons for Elementor
<= 4.11.105
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Qi Addons For Elementor
<= 1.11
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Happy Addons for Elementor
<= 3.23.1
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Flexible PDF Coupons
<= 1.14.11
Insecure Direct Object References (IDOR) vulnerability
5.4
4 hours ago
Load more