Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,774
Mitigations
Mitigation rules
16,529
No official patch
13,309
In triage
1,084
Published soon
114
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
mcp-searxng
< 1.12.0
NPM: SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
5.5
16 minutes ago
mcp-searxng
< 1.2.1
NPM: SearXNG MCP Server: Additional hardened-mode SSRF bypasses
6.3
25 minutes ago
mcp-searxng
< 1.2.1
NPM: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
6.5
25 minutes ago
@contentful/mcp-server
< 1.7.19
NPM: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
7.7
31 minutes ago
@contentful/mcp-tools
< 0.4.5
NPM: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
7.7
31 minutes ago
claude-faf-mcp
<= 5.7.1
NPM: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
7.5
33 minutes ago
faf-mcp
<= 2.1.2
NPM: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
7.5
33 minutes ago
grok-faf-mcp
<= 1.5.2
NPM: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
7.5
33 minutes ago
Elementor Pro
<= 4.2.1
Arbitrary File Upload vulnerability
9
2 hours ago
Welcart e-Commerce
< 2.11.32
Editor+ SQL Injection via CSV Import vulnerability
8.5
7 hours ago
Brizy
< 2.8.19
WordPress Brizy - Page Builder plugin < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset vulnerability
5.9
7 hours ago
Brizy
< 2.8.19
WordPress Brizy - Page Builder plugin < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point vulnerability
6.5
7 hours ago
Contest Gallery
< 30.0.7
Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library vulnerability
2.7
7 hours ago
Classified Listing
< 5.4.4
Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search vulnerability
4.3
7 hours ago
Contest Gallery
< 30.0.7
Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts vulnerability
4.3
7 hours ago
Easy Integration for Dropbox
< 2.2.0
Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX vulnerability
9.3
7 hours ago
miniOrange's Google Authenticator
< 6.2.7
Subscriber+ Arbitrary-Recipient OTP Send vulnerability
4.3
7 hours ago
Meow Gallery
< 5.5.2
Author+ Stored XSS via Attachment Alt-Text vulnerability
5.9
7 hours ago
Ajax Load More
< 8.0.1
Unauthenticated SQL Injection via custom_args vulnerability
9.3
7 hours ago
BNE Testimonials
< 2.0.8.2
Contributor+ Stored XSS via Slider Shortcode vulnerability
6.5
7 hours ago
Load more