Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,427
Mitigations
Mitigation rules
17,087
No official patch
13,368
In triage
1,357
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Login/Signup Popup
< 4.0.2
Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header vulnerability
8.1
12 minutes ago
WCFM Marketplace
<= 3.8.2
Unauthenticated SQL Injection vulnerability
9.3
27 minutes ago
Login/Signup Popup
< 4.0.2
Unauthenticated Account Takeover via Password Reset Code Brute Force vulnerability
8.1
1 hour ago
InfiniteWP Client
< 1.13.6
Unauthenticated Administrator Account Takeover on Multisite vulnerability
8.1
1 hour ago
SoftMarket — Digital Marketplace
<= 1.0.0
Unauthenticated Account Takeover via Email Verification Bypass vulnerability
9.8
1 hour ago
To Do List Member
1.4-1.6
Unauthenticated Stored XSS, File Listing and Deletion vulnerability
8.8
1 hour ago
PuppyFW
<= 0.4.4
Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation vulnerability
8.8
1 hour ago
Out-of-the-Box
2.0-3.8.3
WordPress WP Cloud Plugins - Dropbox (Out-of-the-Box) plugin 2.0-3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
Lets-Box
2.0-3.8.3
WordPress WP Cloud Plugins - Box (Lets-Box) plugin 2.0-3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
Share-one-Drive
2.0-3.8.3
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
Use-your-Drive
2.0-3.8.3
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
wpShopGermany IT-RECHT KANZLEI
1.6-2.3
Unauthenticated RCE vulnerability
9
1 hour ago
Filter Gallery
<= 1.1.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion vulnerability
8.1
2 hours ago
Login with QR
<= 1.0.0
Unauthenticated Authentication Bypass vulnerability
9.8
2 hours ago
The Pressengine
<= 1.0
Unauthenticated Authentication Bypass vulnerability
9.8
2 hours ago
Private Feed Key
<= 0.1
Unauthenticated Authentication Bypass vulnerability
9.8
2 hours ago
Clean Login
< 1.19
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
3 hours ago
All Bootstrap Blocks
<= 1.3.31
Contributor+ Stored XSS vulnerability
7.1
3 hours ago
MasterStudy LMS
3.6.2-3.7.49
Instructor+ Student PII Disclosure vulnerability
2.7
3 hours ago
BookIt
< 2.6.0.5
Bookit Staff+ Appointment PII Disclosure vulnerability
2.7
3 hours ago
Load more