The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total47,655
Mitigations15,355
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<= 2.0.8
SQL Injection vulnerability
8.5
04/06/2026
Sunshine Photo Cart<= 3.6.7
Broken Access Control vulnerability
6.3
02/06/2026
SePay Gateway<= 1.1.20
Sensitive Data Exposure vulnerability
6.5
02/06/2026
Facebook for WooCommerce<= 3.7.0
Open Redirection vulnerability
4.7
26 minutes ago
SVG Support<= 2.5.14
Broken Access Control vulnerability
4.3
29 minutes ago
SeedProd Pro< 6.19.5
Local File Inclusion vulnerability
7.5
1 hour ago
Product Import Export for WooCommerce<= 2.5.6
Broken Access Control vulnerability
4.3
3 hours ago
Advanced Custom Fields<= 6.8.1
Unauthenticated Broken Access Control vulnerability
5.3
5 hours ago
affiliate-toolkit<= 3.8.4
Authenticated (Editor+) Remote Code Execution vulnerability
7.2
5 hours ago
Booking Calendar – Event Calendar<= 2.1.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
5 hours ago
Query Shortcode<= 0.2.1
Authenticated (Contributor+) Local File Inclusion vulnerability
7.5
5 hours ago
NS Product icon badge<= 1.2.4
Reflected Cross-Site Scripting vulnerability
6.1
5 hours ago
Livemesh SiteOrigin Widgets<= 3.9.2
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
5 hours ago
Livemesh Addons for WPBakery Page Builder<= 3.9.4
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
5 hours ago
Livemesh Addons for Beaver Builder<= 3.9.2
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.4
5 hours ago
Enable jQuery Migrate Helper<= 1.4.1
Missing Authorization to Authenticated (Subscriber+) jQuery Version Downgrade vulnerability
6.5
5 hours ago
WPCode<= 2.3.5
Authenticated (Author+) Remote Code Execution vulnerability
8.8
5 hours ago
Firebase Support & Chat Management<= 3.1.1
Missing Authorization to Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
5 hours ago
Login with NEAR<= 0.3.3
Authentication Bypass vulnerability
8.1
5 hours ago
Boost<= 2.0.3
Unauthenticated PHP Object Injection vulnerability
9.8
5 hours ago