The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total48,564
Mitigations15,625
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Generate Security.txt<= 1.0.12
Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion vulnerability
4.3
13 hours ago
Reviews and Rating – Docplanner<= 1.1.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification vulnerability
4.3
13 hours ago
WhatsOrder – Instant Checkout for WooCommerce<= 1.0.1
Unauthenticated Sensitive Information Exposure vulnerability
5.3
13 hours ago
Devs Accounting – Simple Accounting and Invoicing Solution<= 1.2.0
Missing Authorization to Unauthenticated Account Deletion vulnerability
5.3
13 hours ago
Devs Accounting – Simple Accounting and Invoicing Solution<= 1.2.0
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
13 hours ago
24liveblog – live blog tool<= 2.2
Missing Authorization to Authenticated (Author+) Settings Modification vulnerability
4.3
13 hours ago
24liveblog – live blog tool<= 2.2
Authenticated (Contributor+) Exposure of Sensitive Information vulnerability
4.3
13 hours ago
Osiris Signature Banner<= 0.5
Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
4.3
13 hours ago
RentMy Real-Time Rental Management Plugin<= 4.0.4.1
Missing Authorization to Unauthenticated Settings Update vulnerability
5.3
13 hours ago
Advance Nav Menu Manager<= 1.3
Missing Authorization to Authenticated (Subscriber+) Nav Menu Item Modification vulnerability
4.3
13 hours ago
SearchPlus<= 1.7.1
Missing Authorization to Unauthenticated Settings Modification and Deletion vulnerability
5.3
13 hours ago
Assistio<= 1.1.2
Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion vulnerability
4.3
13 hours ago
Secufor_OAuth<= 1.0.7
Missing Authorization to Unauthenticated Account Logout vulnerability
5.3
13 hours ago
MP Customize Login Page<= 1.0
Cross-Site Request Forgery to Settings Update vulnerability
4.3
13 hours ago
Xpro Elementor Addons<= 1.7.2
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.9
15 hours ago
Ultimate Member<= 2.11.4
Authenticated (Contributor+) Account Takeover vulnerability
8.8
1 day ago
Transbank Webpay REST< 1.14.0
Unauthenticated Stored XSS vulnerability
7.1
1 day ago
LBG Zoominoutslider<= 5.4.4
SQL Injection vulnerability
8.5
1 day ago
Vitepos< 3.4.2
Outlet Manager+ Privilege Escalation vulnerability
7.2
1 day ago
Simple File List<= 6.3.7
Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action vulnerability
7.5
1 day ago