Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,578
Mitigations
Mitigation rules
17,172
No official patch
13,370
In triage
1,427
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@aborruso/ckan-mcp-server
<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
1 hour ago
@sync-in/server
<= 2.4.0
NPM: Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
5.3
1 hour ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
6.5
1 hour ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
8.1
1 hour ago
@sync-in/server
<= 2.3.0
NPM: @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
6.8
1 hour ago
@roomi-fields/notebooklm-mcp
>= 1.6.0, < 2.0.3
NPM: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
7.1
1 hour ago
WordPress
<= 7.1.1
Unauthenticated Local File Inclusion to Remote Code Execution vulnerability
9.2
2 hours ago
Ninja Forms
<= 3.15.3
Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
WP Yelp Review Slider
<= 9.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
CTX Feed
<= 6.6.43
Authenticated (Shop Manager+) Path Traversal to File Deletion vulnerability
4.9
2 hours ago
TranslatePress
<= 3.3.5
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Booking Calendar
<= 11.8.3
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
GiveWP
< 4.16.9
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
3 hours ago
Payment Gateway for PayPal on WooCommerce
< 9.2.1
Unauthenticated Payment Bypass vulnerability
5.3
3 hours ago
Meow Gallery
< 5.5.5
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
3 hours ago
Forminator
< 1.57.2.1
Authenticated Privilege Escalation vulnerability
6.6
3 hours ago
Forminator
< 1.57.2.1
Authenticated RCE vulnerability
8.5
4 hours ago
Redux Framework
<= 4.5.13
Authenticated (Subscriber+) Cross-Site Scripting vulnerability
6.5
4 hours ago
NextGEN Gallery
< 4.5.0
Authenticated Arbitrary File Upload vulnerability
9.1
4 hours ago
MC4WP
<= 4.14.0
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
Load more