The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total35,835
Mitigations13,217
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Fancy Product Designer<= 6.4.8
Unauthenticated Server-Side Request Forgery via Race Condition vulnerability
7.2
51 minutes ago
LearnPress<= 4.3.1
Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social vulnerability
6.5
53 minutes ago
Booking Calendar<= 10.14.8
Unauthenticated SQL Injection via dates_to_check vulnerability
9.3
55 minutes ago
Fox LMS1.0.4.7-1.0.5.1
Unauthenticated Privilege Escalation vulnerability
9.8
59 minutes ago
WPCOM Member<= 1.7.16
Authentication Bypass via Weak OTP vulnerability
8.1
1 hour ago
Post Expirator<= 4.9.2
Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure vulnerability
4.3
9 hours ago
Elementor Website Builder<= 3.33.3
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path vulnerability
6.5
9 hours ago
Fancy Product Designer<= 6.4.8
Unauthenticated Full Path Disclosure via 'pdf' Parameter vulnerability
5.3
9 hours ago
Auto Featured Image (Auto Post Thumbnail)<= 4.2.1
Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification vulnerability
4.3
9 hours ago
Dokan Pro<= 4.1.3
Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
5.3
9 hours ago
LearnPress<= 4.3.1
Missing Authorization to Unauthenticated Orders Statistics Exposure vulnerability
5.3
10 hours ago
Modula Image Gallery<= 2.13.3
Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification vulnerability
4.3
10 hours ago
OneSignal – Web Push Notifications<= 3.6.1
Missing Authorization to Unauthenticated Plugin Settings Update vulnerability
5.3
11 hours ago
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress<= 2.0.3
WordPress FluentAuth - Auth Security Plugin plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode vulnerability
6.5
11 hours ago
RegistrationMagic<= 6.0.6.7
Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode vulnerability
6.5
11 hours ago
CC Child Pages<= 2.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'child_pages' Shortcode vulnerability
6.5
11 hours ago
User Registration<= 4.4.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
11 hours ago
Filebird<= 6.5.1
Missing Authorization to Authenticated (Author+) Global Folders Tampering vulnerability
4.3
11 hours ago
Lightweight Accordion<= 1.5.20
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
15 hours ago
Elementor Addon Elements<= 1.14.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
15 hours ago