The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,835
Mitigations13,221
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Login Lockdown<= 2.14
IP Block Bypass vulnerability
5.3
Just now
WPS Visitor Counter<= 1.4.8
Reflected XSS vulnerability
7.1
49 minutes ago
HelloLeads CRM Form Shortcode<= 1.0
Unauthenticated Settings Reset vulnerability
6.5
50 minutes ago
MailerLite – WooCommerce integration<= 3.1.3
WordPress MailerLite - WooCommerce integration plugin <= 3.1.3 - Missing Authorization to Data Deletion vulnerability
6.5
51 minutes ago
Fancy Product Designer<= 6.4.8
Unauthenticated Information Disclosure via 'url' Parameter vulnerability
5.9
59 minutes ago
Fancy Product Designer<= 6.4.8
Unauthenticated Server-Side Request Forgery via Race Condition vulnerability
7.2
4 hours ago
LearnPress<= 4.3.1
Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social vulnerability
6.5
4 hours ago
Booking Calendar<= 10.14.8
Unauthenticated SQL Injection via dates_to_check vulnerability
9.3
4 hours ago
Fox LMS1.0.4.7-1.0.5.1
Unauthenticated Privilege Escalation vulnerability
9.8
4 hours ago
WPCOM Member<= 1.7.16
Authentication Bypass via Weak OTP vulnerability
8.1
4 hours ago
Post Expirator<= 4.9.2
Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure vulnerability
4.3
12 hours ago
Elementor Website Builder<= 3.33.3
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path vulnerability
6.5
12 hours ago
Fancy Product Designer<= 6.4.8
Unauthenticated Full Path Disclosure via 'pdf' Parameter vulnerability
5.3
12 hours ago
Auto Featured Image (Auto Post Thumbnail)<= 4.2.1
Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification vulnerability
4.3
13 hours ago
Dokan Pro<= 4.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
13 hours ago
LearnPress<= 4.3.1
Missing Authorization to Unauthenticated Orders Statistics Exposure vulnerability
5.3
13 hours ago
Modula Image Gallery<= 2.13.3
Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification vulnerability
4.3
13 hours ago
OneSignal – Web Push Notifications<= 3.6.1
Missing Authorization to Unauthenticated Plugin Settings Update vulnerability
5.3
14 hours ago
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress<= 2.0.3
WordPress FluentAuth - Auth Security Plugin plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode vulnerability
6.5
14 hours ago
RegistrationMagic<= 6.0.6.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode vulnerability
6.5
14 hours ago