Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,182
Mitigations
Mitigation rules
17,876
No official patch
13,601
In triage
981
Published soon
105
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Dashboard Notes
<= 1.0.3
Cross Site Request Forgery (CSRF) vulnerability
7.1
40 minutes ago
Before After Image Comparison – Image comparison for WP
<= 1.1.21
Broken Access Control vulnerability
5.4
1 hour ago
WPFunnels
<= 3.13.3
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
All Bootstrap Blocks
<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
2 hours ago
Asgaros Forum
<= 3.4.0
Broken Access Control vulnerability
4.3
2 hours ago
Html5 Audio Player
<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Restrict User Access – Membership Plugin with Force
<= 2.8.1
Broken Access Control vulnerability
5.3
2 hours ago
WP Event Manager
<= 3.4.1
Broken Access Control vulnerability
5.4
2 hours ago
Scripts n Styles
<= 3.5.8
Broken Access Control vulnerability
5.3
2 hours ago
AI Translation for Polylang
<= 1.6.2
Broken Access Control vulnerability
5.4
2 hours ago
JetBlocks For Elementor
<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Ocean Pro Demos
<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
6 hours ago
Ocean eComm Treasure Box
<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
6 hours ago
Redux Framework
<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
6 hours ago
fast-jwt
<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
15 hours ago
@adonisjs/http-server
<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
15 hours ago
fast-jwt
<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
15 hours ago
fast-jwt
>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
15 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
15 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
15 hours ago
Load more