Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,502
Mitigations
Mitigation rules
16,377
No official patch
13,266
In triage
1,146
Published soon
0
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Wholesale Market
<= 2.2.2
Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter vulnerability
8.8
10 minutes ago
KiviCare
<= 4.5.1
Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter vulnerability
8.5
23 minutes ago
Groundhogg
<= 4.5.14
Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter vulnerability
8.5
24 minutes ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
<= 5.1
Unauthenticated Stored Cross-Site Scripting via 'action' Parameter vulnerability
7.1
35 minutes ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
<= 5.1
Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values vulnerability
7.6
43 minutes ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
<= 5.1
Authenticated (Editor+) SQL Injection via 'key' Parameter vulnerability
7.6
44 minutes ago
Form Maker by 10Web
<= 1.15.44
Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause vulnerability
8.5
46 minutes ago
Hydra Booking
<= 1.2.2
Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter vulnerability
6.5
46 minutes ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
<= 4.3.5
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter vulnerability
6.5
1 hour ago
Contest Gallery
<= 30.0.7
Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' vulnerability
7.6
1 hour ago
Beaver Builder
<= 2.10.2.2
Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter vulnerability
5.9
1 hour ago
Image Uploader for Welcart
<= 1.4.6
Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter vulnerability
7.6
1 hour ago
Pinpoint Booking System
<= 2.9.9.6.8
Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter vulnerability
5.3
1 hour ago
Booking calendar, Appointment Booking System
<= 3.2.36
Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action vulnerability
5.3
1 hour ago
Propovoice CRM
<= 1.7.8
Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter vulnerability
7.2
1 hour ago
MaxUpload
<= 1.4.0
Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter vulnerability
10
1 hour ago
Online Booking & Scheduling Calendar for WordPress by vcita
<= 4.6.0
Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter vulnerability
7.1
1 hour ago
Profile Builder
<= 3.16.4
Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter vulnerability
9.8
3 hours ago
Object Sync for Salesforce
<= 2.2.13
Unauthenticated SQL Injection vulnerability
9.3
3 hours ago
6Storage Rentals
<= 2.27.0
Unauthenticated Account Takeover via 'email' Parameter vulnerability
9.8
4 hours ago
Load more