The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,495
Mitigations16,373
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant<= 5.1
Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values vulnerability
7.6
3 minutes ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant<= 5.1
Authenticated (Editor+) SQL Injection via 'key' Parameter vulnerability
7.6
4 minutes ago
Form Maker by 10Web<= 1.15.44
Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause vulnerability
8.5
6 minutes ago
Hydra Booking<= 1.2.2
Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter vulnerability
6.5
6 minutes ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.3.5
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter vulnerability
6.5
20 minutes ago
Contest Gallery<= 30.0.7
Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' vulnerability
7.6
35 minutes ago
Beaver Builder<= 2.10.2.2
Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter vulnerability
5.9
35 minutes ago
Image Uploader for Welcart<= 1.4.6
Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter vulnerability
7.6
37 minutes ago
Pinpoint Booking System<= 2.9.9.6.8
Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter vulnerability
5.3
38 minutes ago
Booking calendar, Appointment Booking System<= 3.2.36
Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action vulnerability
5.3
40 minutes ago
Propovoice CRM<= 1.7.8
Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter vulnerability
7.2
43 minutes ago
MaxUpload<= 1.4.0
Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter vulnerability
10
49 minutes ago
Online Booking & Scheduling Calendar for WordPress by vcita<= 4.6.0
Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter vulnerability
7.1
1 hour ago
Profile Builder<= 3.16.4
Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter vulnerability
9.8
2 hours ago
Object Sync for Salesforce<= 2.2.13
Unauthenticated SQL Injection vulnerability
9.3
3 hours ago
6Storage Rentals<= 2.27.0
Unauthenticated Account Takeover via 'email' Parameter vulnerability
9.8
3 hours ago
bLoyal<= 3.1.611.78
Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings vulnerability
8.8
3 hours ago
RapiSafe – Secure Multi File Upload for Contact Form 7<= 1.0.4
Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters vulnerability
8.6
3 hours ago
User Session Synchronizer<= 1.4.0
Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters vulnerability
9.8
3 hours ago
Frontend Admin by DynamiApps< 3.29.9
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago