Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,233
Mitigations
Mitigation rules
16,192
No official patch
13,189
In triage
1,134
Published soon
8
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Google Tag Manager
<= 1.22.3
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
39 minutes ago
Academy LMS
<= 3.8.2
Subscriber+ Sensitive Information Disclosure vulnerability
6.5
45 minutes ago
ElementsKit Elementor addons Lite
< 3.10.01
Subsite Administrator+ PHP Code Injection vulnerability
7.2
47 minutes ago
JS Help Desk
< 3.1.4
Unauthenticated Arbitrary Ticket File Attachment Upload vulnerability
5.3
47 minutes ago
JS Help Desk
< 3.1.4
Subscriber+ Sensitive Information Disclosure vulnerability
6.5
52 minutes ago
NewStatPress
< 1.4.5
Unauthenticated Stored XSS vulnerability
7.1
54 minutes ago
GiveWP
< 4.16.3
Unauthenticated Payment Gateway Restriction Bypass vulnerability
5.3
1 hour ago
Link Library
< 7.9.4
Reflected Cross-Site Scripting vulnerability
7.1
1 hour ago
Kirki
< 6.0.13
Unauthenticated PHP Object Injection vulnerability
9.8
1 hour ago
Survey Maker
< 5.1.7.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Realtyna Organic IDX plugin
<= 5.3.0
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
WP Go Maps
< 10.1.04
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
FluentCart
< 1.5.3
Unauthenticated Order PII Disclosure vulnerability
7.5
2 hours ago
FlxWoo
< 3.1.1
Unauthenticated Payment Bypass vulnerability
7.5
2 hours ago
Realtyna Organic IDX plugin
<= 5.2.0
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
sequelize
< 6.37.4
NPM: Sequelize: SQL Injection (Oracle DB)
9.8
12 hours ago
hono
< 4.12.34
NPM: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
5.3
12 hours ago
ip-address
<= 10.3.0
NPM: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
7.7
12 hours ago
ip-address
>= 10.1.1, <= 10.2.1
NPM: ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
6.9
12 hours ago
ip-address
>= 10.1.1, <= 10.2.0
NPM: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
6.9
12 hours ago
Load more