Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,252
Mitigations
Mitigation rules
16,213
No official patch
13,190
In triage
1,139
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
flowise
<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
8 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
8 minutes ago
flowise
<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
24 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
24 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
7.2
43 minutes ago
flowise
<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
1 hour ago
flowise-components
<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
8.5
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
6
1 hour ago
Booking Calendar Contact Form
<= 1.0.23
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
WP Event SOlution
< 4.1.16
Unauthenticated Payment Bypass vulnerability
5.3
4 hours ago
WP Travel
< 11.8.1
Unauthenticated Payment Bypass vulnerability
5.3
4 hours ago
Hide My WP Ghost
< 7.0.05
IP Address Spoofing vulnerability
5.4
4 hours ago
Booking Calendar Contact Form
<= 1.0.23
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
4 hours ago
Ultimate Product Catalogue
<= 3.8.6
Authenticated (Contributor+) Arbitrary File Upload vulnerability
10
4 hours ago
Booking Calendar Contact Form
<= 1.1.24
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
Zoner - Real Estate
< 4.2
WordPress Zoner - Real Estate WordPress Theme theme < 4.2 - Real Estate WordPress Theme < 4.2 - Cross-Site Scripting vulnerability
7.1
4 hours ago
Contact Form Builder, Contact Widget
<= 1.6.1
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
Flights & Hotels Booking WP Plugin
<= 2.3
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
WOLF
< 1.1.0
WordPress WOLF plugin < 1.1.0 - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS vulnerability
7.1
5 hours ago
Load more