The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total38,581
Mitigations14,121
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
wpForo Forum<= 2.4.14
Unauthenticated Time-Based SQL Injection vulnerability
9.3
15 minutes ago
WooCommerce Product Table Lite<= 4.6.2
Unauthenticated Time-Based SQL Injection via 'search' Parameter vulnerability
9.3
34 minutes ago
Master Addons for Elementor<= 2.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' vulnerability
6.5
7 hours ago
Quiz Maker<= 6.7.1.7
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
8 hours ago
Advanced AJAX Product Filters<= 3.1.9.6
Authenticated (Author+) PHP Object Injection via Live Composer Compatibility vulnerability
8.8
17 hours ago
Brevo<= 3.3.0
Unauthenticated Authorization Bypass via Type Juggling vulnerability
6.5
18 hours ago
Blog2Social<= 8.7.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification vulnerability
6.5
18 hours ago
Shield Security<= 21.0.8
Cross-Site Request Forgery to SQL Injection vulnerability
9.3
18 hours ago
WooCommerce Checkout Manager<= 7.8.5
Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability
7.5
21 hours ago
Prodigy Commerce<= 3.2.9
Unauthenticated Local File Inclusion via parameters[template_name] vulnerability
8.1
21 hours ago
Orderable<= 1.20.0
Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Installation vulnerability
8.8
22 hours ago
Two Factor (2FA) Authentication via Email<= 1.9.8
Two-Factor Authentication Bypass via token vulnerability
6.5
23 hours ago
Library Management System<= 3.2.1
Unauthenticated SQL Injection vulnerability
9.3
23 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.1.2
Missing Authorization to Sensitive Information Exposure vulnerability
7.5
23 hours ago
Video Conferencing with Zoom< 4.6.6
Unauthenticated SDK Signature Generation vulnerability
7.5
23 hours ago
WP Ultimate CSV Importer<= 7.37
WordPress WP Import - Ultimate CSV XML Importer for WordPress plugin <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name vulnerability
8.5
23 hours ago
s2Member<= 260127
Unauthenticated Privilege Escalation via Account Takeover vulnerability
9.8
23 hours ago
IDonate2.1.5-2.1.9
WordPress IDonate plugin 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function vulnerability
8.8
23 hours ago
Slider Future<= 1.0.5
Unauthenticated Arbitrary File Upload vulnerability
10
23 hours ago
Lizza LMS Pro<= 1.0.3
Unauthenticated Privilege Escalation vulnerability
9.8
1 day ago