The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total39,377
Mitigations14,650
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
KiviCare<= 4.1.2
WordPress KiviCare - Clinic & Patient Management System (EHR) plugin <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token vulnerability
9.8
9 hours ago
KiviCare<= 4.1.2
Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard vulnerability
8.2
9 hours ago
Post SMTP<= 3.8.0
Unauthenticated Stored Cross-Site Scripting via 'event_type' vulnerability
7.1
9 hours ago
Slimstat Analytics<= 5.3.5
Unauthenticated Stored Cross-Site Scripting via 'fh' vulnerability
7.1
9 hours ago
Restrict Content<= 3.2.24
WordPress Membership Plugin - Restrict Content plugin <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirect vulnerability
4.3
9 hours ago
Simply Schedule Appointments<= 1.6.10.0
Unauthenticated SQL Injection via 'fields' Parameter vulnerability
9.3
9 hours ago
Aimogen Pro<= 2.7.5
Unauthenticated Privilege Escalation via Arbitrary Function Call vulnerability
9.8
9 hours ago
ilGhera Carta Docente for WooCommerce<= 1.5.0
Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter vulnerability
6.5
16 hours ago
CM Custom WordPress Reports and Analytics<= 1.2.7
Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels vulnerability
5.9
16 hours ago
RockPress<= 1.0.17
Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via AJAX Actions vulnerability
5.4
16 hours ago
Instant Popup Builder<= 1.1.7
Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter vulnerability
5.3
20 hours ago
Add Custom Fields to Media<= 2.0.3
Cross-Site Request Forgery to Custom Field Deletion via 'delete' Parameter vulnerability
4.3
20 hours ago
Draft List<= 2.6.2
Authenticated (Contributor+) Stored Cross-Site Scripting via 'display_name' Parameter vulnerability
5.9
21 hours ago
Download Manager<= 3.3.49
Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability
4.3
21 hours ago
Info Cards<= 2.0.7
Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes vulnerability
6.5
21 hours ago
NextGEN Gallery<= 4.0.4
WordPress Photo Gallery, Sliders, Proofing and Themes - NextGEN Gallery plugin <= 4.0.4 - Authenticated (Author+) Local File Inclusion vulnerability
7.2
21 hours ago
Code Embed<= 2.5.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields vulnerability
6.5
1 day ago
Post SMTP<= 3.8.0
Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite vulnerability
5.4
1 day ago
JSON Content Importer< 2.0.10
Contributor+ Stored XSS vulnerability
6.5
1 day ago
Ultimate Post Kit<= 4.0.21
Broken Access Control vulnerability
6.4
2 days ago