The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,899
Mitigations16,074
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
security-ninja-premium< 5.290
Two-Factor Authentication Bypass vulnerability
7.5
11 minutes ago
微信二维码登陆<= 1.3
Unauthenticated Account Takeover vulnerability
9.8
17 minutes ago
FacturaONE para WooCommerce con VeriFactu< 5.37
Unauthenticated Remote Code Execution vulnerability
10
27 minutes ago
Realtyna Organic IDX plugin< 5.3.0
Unauthenticated Arbitrary File Upload to Remote Code Execution vulnerability
10
36 minutes ago
Post Status Notifier Lite< 1.13.0
Reflected XSS vulnerability
7.1
44 minutes ago
Custom Fields Account Registration For Woocommerce< 1.4
Unauthenticated Privilege Escalation vulnerability
9.8
53 minutes ago
Advanced Responsive Video Embedder10.8.7
Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter vulnerability
9.8
1 hour ago
MemberGlut< 1.1.5
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
1 hour ago
Printcart Web to Print Product Designer for WooCommerce< 2.5.3
Unauthenticated Arbitrary File Read and Server-Side Request Forgery vulnerability
8.6
1 hour ago
MainWP Child< 6.1.2
Unauthenticated Administrator Authentication Bypass vulnerability
9.8
1 hour ago
style-dictionary>= 4.3.0, < 5.4.4
Prototype Pollution in convertTokenData utility function
8.8
9 hours ago
@hypequery/clickhouse< 2.0.2
NPM: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
9.8
9 hours ago
@nocobase/plugin-collection-sql< 2.0.62
NPM: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
6.8
11 hours ago
qti-neon1.0.0
NPM: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
8.6
15 hours ago
@novu/application-generic< 3.17.0
NPM: @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
6.8
17 hours ago
@wakaru/cli>= 1.0.0, < 1.4.0
NPM: @wakaru/cli arbitrary file write during bundle unpack
7.1
17 hours ago
Kirki<= 6.0.13
Arbitrary File Deletion vulnerability
6.8
2 days ago
Thrive Leads Version<= 10.9.2
Broken Access Control vulnerability
6.5
2 days ago
ЮKassa для WooCommerce<= 2.16.1
Sensitive Data Exposure vulnerability
6.5
2 days ago
RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg<= 1.5.1
Broken Access Control vulnerability
6.5
2 days ago