Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,671
Mitigations
Mitigation rules
16,467
No official patch
13,287
In triage
1,112
Published soon
65
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
magicmirror
< 2.37.0
NPM: MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
4.3
2 hours ago
@geolens/sdk
< 1.2.3
NPM: GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
7.5
2 hours ago
magicmirror
< 2.37.0
NPM: MagicMirror: ssrf calendar .js
6.3
2 hours ago
magicmirror
< 2.37.0
NPM: MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
6.3
2 hours ago
magicmirror
< 2.37.0
NPM: MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
2.3
2 hours ago
WP Travel Engine
<= 6.8.4
Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter vulnerability
7.5
3 hours ago
StoreEngine
<= 2.1.1
Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL vulnerability
6.5
3 hours ago
ProSolution WP Client
< 2.0.9
Subscriber+ SSRF via proSol_url_validate vulnerability
6.4
3 hours ago
WPC Admin Columns
< 2.3.4
Subscriber+ Arbitrary User/Post/Term Meta Disclosure vulnerability
6.5
3 hours ago
WP Photo Album Plus
< 9.2.07.002
Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal vulnerability
5.3
3 hours ago
WP Photo Album Plus
< 9.2.07.002
Reflected XSS via lbstart vulnerability
7.1
3 hours ago
WP Travel Engine
< 6.8.5
Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart vulnerability
6.5
3 hours ago
KiviCare
< 4.5.2
Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint vulnerability
8.5
3 hours ago
RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
< 1.5.2
Subscriber+ Stored XSS vulnerability
6.5
3 hours ago
wpForo Forum
< 3.1.2
Subscriber+ Stored XSS vulnerability
6.5
3 hours ago
Gallery For Google Photos
< 1.2.1
Unauthenticated Google OAuth Token Disclosure vulnerability
7.5
3 hours ago
WP Directory Kit
< 1.5.6
Subscriber+ SQL Injection via section Parameter vulnerability
8.5
3 hours ago
WP Directory Kit
< 1.5.6
Unauthenticated SQL Injection via search_location and search_category vulnerability
9.3
3 hours ago
Ezoic
< 2.23.1
Unauthenticated Database Export via Content Export REST Routes vulnerability
7.5
3 hours ago
The School Management – Education & Learning Management
<= 5.4
Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter vulnerability
8.5
3 hours ago
Load more