The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,865
Mitigations13,236
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Html5 Audio Player2.4.0-2.5.1
Unauthenticated Server-Side Request Forgery vulnerability
7.2
Invalid date
Image Photo Gallery Final Tiles Grid<= 3.6.7
Missing Authorization to Authenticated (Contributor+) Gallery Management vulnerability
5.4
43 minutes ago
myCred<= 2.9.7.1
Missing Authorization to Sensitive Information Exposure vulnerability
4.3
44 minutes ago
Colibri Page Builder<= 1.0.345
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
46 minutes ago
BA Book Everything<= 1.8.14
Authenticated (Contributor+) Stored Cross-Site Scripting via babe-search-form Shortcode vulnerability
6.5
47 minutes ago
Simply Schedule Appointments<= 1.6.9.16
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
53 minutes ago
Sweet Energy Efficiency<= 1.0.6
Missing Authorization to Authenticated (Subscriber+) Arbitrary Graph Deletion vulnerability
4.3
1 hour ago
Prime Slider – Addons For Elementor<= 4.0.9
Authenticated (Subscriber+) Server-Side Request Forgery vulnerability
4.3
1 hour ago
HUSKY<= 1.3.7.3
Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' vulnerability
4.3
1 hour ago
Ultimate Member<= 2.11.0
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' vulnerability
6.5
15 hours ago
Demo Importer Plus<= 2.0.8
Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation vulnerability
8.8
15 hours ago
OpenID Connect Generic Client<= 3.10.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
1 day ago
NextGEN Gallery<= 3.59.12
Authenticated (Contributor+) Local File Inclusion via 'template' vulnerability
8.8
1 day ago
Events Manager<= 7.2.2.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode vulnerability
6.5
1 day ago
Embed Any Document<= 2.7.10
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 day ago
Page Builder: Live Composer<= 2.0.2
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
6.5
1 day ago
Ultimate Member<= 2.11.0
Authenticated (Subscriber+) Profile Privacy Setting Bypass vulnerability
4.3
1 day ago
HTML Forms<= 1.6.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 day ago
Zephyr Project Manager<= 3.3.203
Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery vulnerability
4.9
1 day ago
BP Better Messages<= 2.10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 day ago