The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,281
Mitigations17,430
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WPMobile.App<= 11.82
Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter vulnerability
9.8
1 hour ago
Otter - Gutenberg Block<= 3.2.6
Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget vulnerability
3.1
11 hours ago
Listdom<= 6.1.1
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
11 hours ago
LatePoint<= 5.7.1
Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration vulnerability
5.3
11 hours ago
MultiVendorX<= 5.0.18
Authenticated (Store Manager+) SQL Injection vulnerability
6.5
11 hours ago
Ninja Forms<= 3.15.4
Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission vulnerability
7.1
12 hours ago
Ninja Forms File Uploads Extension<= 3.3.34
WordPress Ninja Forms - File Uploads plugin <= 3.3.34 - Unauthenticated Arbitrary File Upload vulnerability
10
13 hours ago
Super Forms<= 6.3.316
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
13 hours ago
Super Forms<= 6.3.316
Unauthenticated Path Traversal to Arbitrary File Read vulnerability
7.5
13 hours ago
DevKit Pro<= 2.3.0
Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow vulnerability
9.8
14 hours ago
CTX Feed Pro<= 7.6.12
Authenticated (Administrator+) Remote Code Execution vulnerability
7.2
14 hours ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
6.8
14 hours ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9.9
14 hours ago
vm2<= 3.11.6
host-realm require() is reachable from sandboxed scripts
8.6
14 hours ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
10
14 hours ago
vm2<= 3.11.6
NPM: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
9.9
14 hours ago
vm2<= 3.11.6
NPM: vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
8.5
14 hours ago
vm2<= 3.11.6
NPM: vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
9.9
14 hours ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
4
14 hours ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
9
14 hours ago