Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,425
Mitigations
Mitigation rules
16,337
No official patch
13,248
In triage
1,150
Published soon
44
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Events Manager
< 7.4.1
Subscriber+ Booking Consent Record Tampering via SQL Injection vulnerability
3.1
41 minutes ago
Form Maker by 10Web
< 1.15.45
Subscriber+ SQL Injection via display_name vulnerability
8.5
42 minutes ago
WP Photo Album Plus
< 9.2.07.002
Unauthenticated Option Disclosure via gettogo vulnerability
5.3
45 minutes ago
Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager
< 0.0.10
Subscriber+ MaxMind License Key Update vulnerability
5.4
47 minutes ago
User Access Manager
< 2.3.15
Unauthenticated Restricted Content Disclosure via REST API vulnerability
5.3
48 minutes ago
PowerPress Podcasting
< 11.17.1
Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL vulnerability
4.9
53 minutes ago
Total Upkeep
< 1.17.3
Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) vulnerability
7.3
53 minutes ago
Welcart e-Commerce
< 2.11.34
Author+ Stored XSS via Product Name vulnerability
5.9
57 minutes ago
Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager
< 0.0.10
Subscriber+ Consent Settings Update and Consent Log Disclosure vulnerability
5.4
59 minutes ago
Patterns Kit
<= 1.0.3
Contributor+ Stored XSS via YouTube Popup Link vulnerability
6.5
1 hour ago
Import WP
< 2.14.23
Unauthenticated Sensitive Information Exposure via Export File Download vulnerability
5.3
1 hour ago
WP Crowdfunding
< 2.2.1
Subscriber+ Campaign Creation via Missing Authorization vulnerability
4.3
1 hour ago
WP Crowdfunding
< 2.2.1
Subscriber+ Campaign Update Modification via IDOR vulnerability
4.3
1 hour ago
@trigger.dev/core
>= 3.3.8, <= 4.5.5
NPM: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
8.5
11 hours ago
hashi-vault-js
<= 0.5.1
NPM: hashi-vault-js: Vault token and secret values exposed in thrown errors
0
17 hours ago
ep_etherpad-lite
>= 2.6.0, <= 3.0.0
NPM: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
6.8
17 hours ago
ep_etherpad-lite
<= 3.0.0
NPM: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
4.2
18 hours ago
ep_etherpad-lite
>= 2.1.0, <= 3.0.0
NPM: ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
6.1
18 hours ago
User Registration
<= 5.2.6
Broken Access Control vulnerability
5.3
19 hours ago
InstaWP Connect
<= 0.1.3.7
Broken Access Control vulnerability
5.3
22 hours ago
Load more