Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,548
Mitigations
Mitigation rules
16,395
No official patch
13,257
In triage
1,149
Published soon
13
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Admin Custom Login
<= 3.6.4
Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting vulnerability
5.9
27 minutes ago
ECS – Ele Custom Skin for Elementor
< 4.3.8
Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers vulnerability
3.8
28 minutes ago
Backup Migration
< 2.1.7
Admin+ Privilege Escalation via Post-Restore Auto-Login vulnerability
7.2
29 minutes ago
Product Feed PRO for WooCommerce
< 13.5.7
Unauthenticated Feed Configuration Disclosure vulnerability
5.3
30 minutes ago
ECS – Ele Custom Skin for Elementor
< 4.3.8
Contributor+ Stored XSS via Dynamic Repeater Bindings vulnerability
6.5
31 minutes ago
Simply Schedule Appointments
< 1.6.12.17
Team Member+ User Email Disclosure via Users and Customers REST Endpoints vulnerability
2.7
31 minutes ago
ECS – Ele Custom Skin for Elementor
< 4.3.8
Unauthenticated Private Content Disclosure via ecsload vulnerability
5.3
32 minutes ago
Multilingual CMS
<= 4.9.5
Authenticated (Translator+) SQL Injection via 'sorting' Parameter vulnerability
8.5
36 minutes ago
Link Library
<= 7.9.4
Unauthenticated Arbitrary File Deletion via link_url Parameter vulnerability
8.6
36 minutes ago
Templately
<= 3.7.1
Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch vulnerability
8.8
41 minutes ago
Real Estate Manager Pro
<= 12.8.6
Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision vulnerability
8.8
49 minutes ago
mlflow
< 3.15.0
NPM: MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
7.1
10 hours ago
mlflow
< 3.15.0
NPM: MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
6.5
10 hours ago
9router
<= 0.5.4
NPM: 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
8.6
10 hours ago
chrome-devtools-mcp
>= 0.24.0, <= 1.0.1
NPM: chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
6.1
10 hours ago
Forminator
<= 1.56.1
Unauth. Arbitrary File Upload
9.8
13 hours ago
ep_etherpad-lite
<= 1.8.14
NPM: Etherpad has stored XSS in HTML export via unescaped attribute-pool values
8.7
14 hours ago
ep_etherpad-lite
<= 1.8.14
NPM: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
0
14 hours ago
vm2
<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
14 hours ago
vm2
<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
14 hours ago
Load more