The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total47,804
Mitigations15,432
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<= 2.0.8
SQL Injection vulnerability
8.5
04/06/2026
Photo Gallery by 10Web<= 1.8.41
SQL Injection vulnerability
7.6
18 minutes ago
Content Visibility for Divi Builder<= 4.02
Authenticated (Contributor+) Remote Code Execution vulnerability
8.8
32 minutes ago
SP Project & Document Manager <= 4.71
Missing Authorization to Unauthenticated Arbitrary File Information Disclosure vulnerability
7.5
46 minutes ago
ARMember Premium<= 7.3.1
Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation vulnerability
9.8
55 minutes ago
ARMember Premium<= 7.3.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
59 minutes ago
ARMember Premium<= 7.3.1
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
MasterStudy LMS Pro<= 4.8.20
Authenticated (Instructor+) SQL Injection vulnerability
8.5
22 hours ago
Sunshine Photo Cart<= 3.6.7
Broken Access Control vulnerability
6.3
1 day ago
Elementor Website Builder<= 4.1.0
Broken Access Control vulnerability
5.4
1 day ago
Crew HRM<= 1.2.2
Broken Access Control vulnerability
5.4
1 day ago
Progress Planner<= 1.9.0
Cross Site Scripting (XSS) vulnerability
5.9
1 day ago
EmergencyWP – Dead Man's switch & legacy deliverance<= 1.4.2
Cross-Site Request Forgery to Plugin Settings Update vulnerability
4.3
1 day ago
Passeum Ticketing<= 1.0
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
1 day ago
FPW Category Thumbnails<= 1.9.5
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
2 days ago
hiWeb Migration Simple<= 2.0.0.1
Reflected Cross-Site Scripting vulnerability
7.1
2 days ago
rognone<= 0.6.2
Reflected Cross-Site Scripting vulnerability
7.1
2 days ago
rognone<= 0.6.2
Reflected Cross-Site Scripting vulnerability
7.1
2 days ago
Simple Custom Login Page<= 1.0.3
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
7.1
2 days ago
Spectra<= 2.19.25
Authenticated (Contributor+) Remote Code Execution vulnerability
8.8
2 days ago