Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,712
Mitigations
Mitigation rules
16,886
No official patch
13,325
In triage
1,105
Published soon
15
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Greenshift
< 13.2.0
Contributor+ SSRF vulnerability
4.1
2 hours ago
Masteriyo - LMS
1.18.0-2.3.3
Instructor+ Stored XSS vulnerability
5.9
2 hours ago
Stripe Payments
< 2.1.4
Open Redirect vulnerability
4.7
2 hours ago
My Private Site
< 4.2.3
Unauthenticated Sensitive Information Exposure vulnerability
3.7
2 hours ago
Stripe Payments
< 2.1.4
Unauthenticated Product Substitution vulnerability
5.3
2 hours ago
Post Grid, Post Carousel, & List Category Posts – by Smart Post Show
4.0.0-4.0.7
Contributor+ Private and Protected Post Content Disclosure vulnerability
2.7
2 hours ago
Post Grid, Post Carousel, & List Category Posts – by Smart Post Show
4.0.0-4.0.7
Unauthenticated Password-Protected Post Content and post_password Disclosure vulnerability
5.3
2 hours ago
Search Atlas SEO
< 2.6.24
Subscriber+ Google Service Account Credential Overwrite/Deletion vulnerability
5.4
2 hours ago
Joli Table Of Contents
2.0.0-2.8.0
Admin+ Stored XSS vulnerability
5.9
2 hours ago
JCH Optimize
4.2.1-5.0.0
Admin+ Path Traversal vulnerability
2.7
2 hours ago
@typespec/spector
<= 0.1.0-alpha.26
NPM: TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
7.5
10 hours ago
WP File Download
<= 6.3.8
Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter vulnerability
6.5
12 hours ago
Abandoned Cart Pro for WooCommerce
<= 10.7.1
Missing Authorization to Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
12 hours ago
Gravity Forms
<= 2.10.5
Unauthenticated Stored Cross-Site Scripting via Post Body Field Value vulnerability
7.1
12 hours ago
W3 Total Cache
<= 2.10.5
Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator vulnerability
7.1
12 hours ago
Ninja Forms
<= 3.15.1
Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key vulnerability
7.1
12 hours ago
Spam protection, AntiSpam, FireWall by CleanTalk
<= 6.86
Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder vulnerability
7.1
12 hours ago
Divi
<= 4.27.6
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter vulnerability
6.5
12 hours ago
Divi
<= 4.27.6
Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter vulnerability
4.9
12 hours ago
Hummingbird
<= 3.21.0
WordPress Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN plugin <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log vulnerability
9
12 hours ago
Load more