Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,175
Mitigations
Mitigation rules
16,181
No official patch
13,189
In triage
1,133
Published soon
8
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
postcss
<= 8.5.22
NPM: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
6.3
49 minutes ago
brace-expansion
< 1.1.18
NPM: brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
7.5
1 hour ago
@angular/core
<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
1 hour ago
@angular/compiler
<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
1 hour ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
8.6
1 hour ago
@angular/common
<= 19.2.25
NPM: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
8.8
2 hours ago
VikBooking Hotel Booking Engine & PMS
<= 1.8.13
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
WPify Woo Czech
<= 5.4.16
Authenticated (Shop Manager+) Privilege Escalation vulnerability
7.2
5 hours ago
Checkout Field Editor for WooCommerce (Pro)
<= 3.7.7
Authenticated (Subscriber+) Path Traversal to Arbitrary File Read vulnerability
6.5
5 hours ago
Nexter Blocks
<= 5.0.0
Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion vulnerability
4.3
6 hours ago
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
<= 2.1.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
6 hours ago
VikBooking Hotel Booking Engine & PMS
<= 1.8.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
6 hours ago
Paid Memberships Pro
<= 3.8.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
6 hours ago
Tablesome
< 1.1.31
Unauthenticated Post Creation and Modification vulnerability
6.5
6 hours ago
Contact Form Entries
< 1.5.3
Reflected XSS vulnerability
7.1
6 hours ago
Quiz And Survey Master
< 11.1.3
Unauthenticated User Enumeration and Password Oracle vulnerability
5.3
6 hours ago
Bookly
< 27.8
Unauthenticated SQL Injection vulnerability
9.3
6 hours ago
Hotel Booking Lite
< 6.0.4
Subscriber+ Sensitive Data Disclosure vulnerability
7.5
6 hours ago
Remote API
<= 0.2
Unauthenticated PHP Object Injection vulnerability
9.8
7 hours ago
Ultimate Addons for WPBakery Page Builder
< 3.21.4
Unauthenticated Custom Icon Font Deletion vulnerability
6.5
7 hours ago
Load more