Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,404
Mitigations
Mitigation rules
16,336
No official patch
13,249
In triage
1,146
Published soon
44
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@trigger.dev/core
>= 3.3.8, <= 4.5.5
NPM: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
8.5
43 minutes ago
hashi-vault-js
<= 0.5.1
NPM: hashi-vault-js: Vault token and secret values exposed in thrown errors
0
7 hours ago
ep_etherpad-lite
>= 2.6.0, <= 3.0.0
NPM: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
6.8
7 hours ago
ep_etherpad-lite
<= 3.0.0
NPM: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
4.2
7 hours ago
ep_etherpad-lite
>= 2.1.0, <= 3.0.0
NPM: ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
6.1
7 hours ago
User Registration
<= 5.2.6
Broken Access Control vulnerability
5.3
8 hours ago
InstaWP Connect
<= 0.1.3.7
Broken Access Control vulnerability
5.3
11 hours ago
WP Event SOlution
< 4.1.20
Unauthenticated Account Creation via Waiting List Endpoint vulnerability
5.3
14 hours ago
KiviCare
< 4.5.2
Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR vulnerability
6.5
14 hours ago
WP Event SOlution
< 4.1.20
Contributor+ Order Information Disclosure via IDOR vulnerability
4.3
14 hours ago
WP Event SOlution
< 4.1.20
Contributor+ Customer PII Disclosure via REST API vulnerability
4.3
14 hours ago
LearnPress
< 4.4.4
Subscriber+ Sensitive Information Exposure via AI Assistant vulnerability
4.3
14 hours ago
Tourmaster
< 5.4.8
Stored XSS vulnerability
7.1
15 hours ago
WP Photo Album Plus
< 9.2.04.003
Subscriber+ Stored XSS vulnerability
6.5
15 hours ago
CubeWP
<= 1.1.30
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
15 hours ago
WordPress
<= 7.0.3
Authenticated (Author+) File Type Confusion to Remote Code Execution vulnerability
9.1
1 day ago
GiveWP
< 4.16.6
Cross Site Scripting (XSS) vulnerability
6.5
1 day ago
Revolut Gateway for WooCommerce
< 4.22.10
Broken Access Control vulnerability
5.3
1 day ago
GiveWP
< 4.16.6
Broken Access Control vulnerability
5.3
1 day ago
MailChimp For WooCommerce
< 6.2
SQL Injection vulnerability
7.6
1 day ago
Load more