The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,321
Mitigations14,611
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Contextual Related Posts< 4.2.2
Broken Access Control vulnerability
5.3
9 hours ago
Writeprint Stylometry<= 0.1
Reflected Cross-Site Scripting via 'p' Parameter vulnerability
7.1
11 hours ago
[CR]Paid Link Manager<= 0.5
Reflected Cross-Site Scripting vulnerability
7.1
12 hours ago
WP Go Maps<= 10.0.05
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
6.5
12 hours ago
Duplicate Post<= 4.5
Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability
5.4
16 hours ago
Subscriptions for WooCommerce<= 1.9.2
Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability
5.3
16 hours ago
Royal Elementor Addons<= 1.7.1049
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
5.3
16 hours ago
Booster for WooCommerce< 7.11.3
Broken Access Control vulnerability
5.3
1 day ago
WowStore<= 4.4.3
WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
9.3
1 day ago
NEX-Forms<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id vulnerability
7.5
1 day ago
NEX-Forms<= 9.1.9
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license vulnerability
4.3
1 day ago
WP User Frontend<= 4.2.8
Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability
5.3
1 day ago
Wicked Folders<= 4.1.0
Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion vulnerability
4.3
1 day ago
Thim Elementor Kit<= 1.3.7
Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
5.3
1 day ago
Master Addons for Elementor<= 2.1.3
Cross Site Scripting (XSS) vulnerability
5.9
2 days ago
WP EasyPay<= 4.2.11
Broken Access Control vulnerability
5.4
2 days ago
Modern Events Calendar<= 7.29.0
Broken Access Control vulnerability
5.3
2 days ago
Flexmls® IDX<= 3.15.9
Reflected Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Jannah<= 7.6.3
Local File Inclusion vulnerability
8.1
2 days ago
LearnPress &#8211; Sepay Payment<= 4.0.0
Broken Authentication vulnerability
7.5
2 days ago