Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,669
Mitigations
Mitigation rules
16,467
No official patch
13,287
In triage
1,112
Published soon
65
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
magicmirror
< 2.37.0
NPM: MagicMirror: ssrf calendar .js
6.3
16 minutes ago
magicmirror
< 2.37.0
NPM: MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
6.3
16 minutes ago
magicmirror
< 2.37.0
NPM: MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
2.3
16 minutes ago
WP Travel Engine
<= 6.8.4
Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter vulnerability
7.5
57 minutes ago
StoreEngine
<= 2.1.1
Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL vulnerability
6.5
58 minutes ago
ProSolution WP Client
< 2.0.9
Subscriber+ SSRF via proSol_url_validate vulnerability
6.4
59 minutes ago
WPC Admin Columns
< 2.3.4
Subscriber+ Arbitrary User/Post/Term Meta Disclosure vulnerability
6.5
59 minutes ago
WP Photo Album Plus
< 9.2.07.002
Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal vulnerability
5.3
1 hour ago
WP Photo Album Plus
< 9.2.07.002
Reflected XSS via lbstart vulnerability
7.1
1 hour ago
WP Travel Engine
< 6.8.5
Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart vulnerability
6.5
1 hour ago
KiviCare
< 4.5.2
Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint vulnerability
8.5
1 hour ago
RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
< 1.5.2
Subscriber+ Stored XSS vulnerability
6.5
1 hour ago
wpForo Forum
< 3.1.2
Subscriber+ Stored XSS vulnerability
6.5
1 hour ago
Gallery For Google Photos
< 1.2.1
Unauthenticated Google OAuth Token Disclosure vulnerability
7.5
1 hour ago
WP Directory Kit
< 1.5.6
Subscriber+ SQL Injection via section Parameter vulnerability
8.5
1 hour ago
WP Directory Kit
< 1.5.6
Unauthenticated SQL Injection via search_location and search_category vulnerability
9.3
1 hour ago
Ezoic
< 2.23.1
Unauthenticated Database Export via Content Export REST Routes vulnerability
7.5
1 hour ago
The School Management – Education & Learning Management
<= 5.4
Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter vulnerability
8.5
1 hour ago
WPAdverts
<= 2.3.2
Missing Authorization to Unauthenticated Sensitive Information Disclosure vulnerability
7.5
1 hour ago
ShopMonitor.io
< 1.2.0
Unauthenticated Administrator Account Takeover vulnerability
9.8
1 hour ago
Load more