The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,425
Mitigations16,337
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Events Manager< 7.4.1
Subscriber+ Booking Consent Record Tampering via SQL Injection vulnerability
3.1
41 minutes ago
Form Maker by 10Web< 1.15.45
Subscriber+ SQL Injection via display_name vulnerability
8.5
42 minutes ago
WP Photo Album Plus< 9.2.07.002
Unauthenticated Option Disclosure via gettogo vulnerability
5.3
45 minutes ago
Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager< 0.0.10
Subscriber+ MaxMind License Key Update vulnerability
5.4
47 minutes ago
User Access Manager< 2.3.15
Unauthenticated Restricted Content Disclosure via REST API vulnerability
5.3
48 minutes ago
PowerPress Podcasting< 11.17.1
Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL vulnerability
4.9
53 minutes ago
Total Upkeep< 1.17.3
Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) vulnerability
7.3
53 minutes ago
Welcart e-Commerce< 2.11.34
Author+ Stored XSS via Product Name vulnerability
5.9
57 minutes ago
Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager< 0.0.10
Subscriber+ Consent Settings Update and Consent Log Disclosure vulnerability
5.4
59 minutes ago
Patterns Kit<= 1.0.3
Contributor+ Stored XSS via YouTube Popup Link vulnerability
6.5
1 hour ago
Import WP< 2.14.23
Unauthenticated Sensitive Information Exposure via Export File Download vulnerability
5.3
1 hour ago
WP Crowdfunding< 2.2.1
Subscriber+ Campaign Creation via Missing Authorization vulnerability
4.3
1 hour ago
WP Crowdfunding< 2.2.1
Subscriber+ Campaign Update Modification via IDOR vulnerability
4.3
1 hour ago
@trigger.dev/core>= 3.3.8, <= 4.5.5
NPM: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
8.5
11 hours ago
hashi-vault-js<= 0.5.1
NPM: hashi-vault-js: Vault token and secret values exposed in thrown errors
0
17 hours ago
ep_etherpad-lite>= 2.6.0, <= 3.0.0
NPM: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
6.8
17 hours ago
ep_etherpad-lite<= 3.0.0
NPM: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
4.2
18 hours ago
ep_etherpad-lite>= 2.1.0, <= 3.0.0
NPM: ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
6.1
18 hours ago
User Registration<= 5.2.6
Broken Access Control vulnerability
5.3
19 hours ago
InstaWP Connect<= 0.1.3.7
Broken Access Control vulnerability
5.3
22 hours ago