The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,641
Mitigations14,806
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Auto Post Scheduler<= 1.84
Cross-Site Request Forgery to Stored Cross-Site Scripting via aps_options_page vulnerability
7.1
7 hours ago
WooCommerce Payments<= 10.5.1
Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax vulnerability
6.5
7 hours ago
Kubio AI Page Builder<= 2.7.0
Cross Site Scripting (XSS) vulnerability
6.5
8 hours ago
Loco Translate<= 2.8.2
Reflected Cross-Site Scripting via 'update_href' Parameter vulnerability
7.1
10 hours ago
Oxygen<= 6.0.8
Unauthenticated Server-Side Request Forgery via route_path vulnerability
7.2
10 hours ago
Gravity SMTP<= 2.1.4
Unauthenticated Sensitive Information Exposure via REST API vulnerability
7.5
11 hours ago
Everest Forms Pro<= 1.9.12
Unauthenticated Remote Code Execution via Calculation Field vulnerability
10
11 hours ago
Contact Form by Supsystic<= 1.7.36
Unauthenticated Server-Side Template Injection via Prefill Functionality vulnerability
10
11 hours ago
Ibtana<= 1.2.5.7
WordPress Ibtana - WordPress Website Builder plugin <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
18 hours ago
TrueBooker<= 1.1.4
WordPress Truebooker - Appointment Booking and Scheduler Plugin plugin <= 1.1.4 - Sensitive Information Exposure via Views Files vulnerability
5.3
18 hours ago
Debugger & Troubleshooter<= 1.3.2
Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation vulnerability
9.8
21 hours ago
Fluent Booking<= 2.0.01
Unauthenticated Stored Cross-Site Scripting via Multiple Parameters vulnerability
7.1
1 day ago
Ultimate Member<= 2.11.2
Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag vulnerability
8
1 day ago
Blackhole for Bad Bots<= 3.8
Unauthenticated Stored Cross-Site Scripting via User-Agent HTTP Header vulnerability
7.1
1 day ago
LeadConnector< 3.0.22
Unauthenticated Rest Call vulnerability
6.5
1 day ago
Shared Files< 1.7.58
Contributor+ Arbitrary File Download vulnerability
6.5
1 day ago
Frontend Admin by DynamiApps<= 3.28.31
Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts vulnerability
7.2
1 day ago
FloristPress<= 7.8.2
Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability
7.1
1 day ago
JS Help Desk<= 3.0.4
WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability
9.3
1 day ago
SureForms<= 2.5.2
Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
7.5
1 day ago