Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,917
Mitigations
Mitigation rules
16,087
No official patch
13,136
In triage
1,164
Published soon
32
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
mathlive
<= 0.109.2
NPM: mathlive's Lack of Escaping of HTML allows for XSS
6.3
4 hours ago
@aws/agentcore
>= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0
NPM: AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
9
6 hours ago
@dynatrace-oss/dynatrace-mcp-server
< 1.8.7
NPM: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
3.7
6 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
8.3
7 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped enum string values
8.3
7 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
8.3
7 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
6.1
7 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
8.3
7 hours ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
7.4
7 hours ago
WP Compress
< 7.10.04
Reflected XSS vulnerability
7.1
10 hours ago
Sina Extension for Elementor
< 3.10.2
Reflected XSS vulnerability
7.1
10 hours ago
MPG
< 4.1.8
Reflected XSS vulnerability
7.1
10 hours ago
Simply Schedule Appointments
< 1.6.12.4
Unauthenticated Stored XSS vulnerability
7.1
10 hours ago
WowOptin
< 1.4.38
Unauthenticated Opt-in Deactivation and Template Row Injection vulnerability
7.5
10 hours ago
Software Issue Manager
< 5.1.0
Unauthenticated SQL Injection vulnerability
9.3
10 hours ago
Document Gallery
< 5.1.1
Reflected XSS vulnerability
7.1
11 hours ago
Praison SEO WordPress
< 5.0.7
Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) vulnerability
7.5
11 hours ago
CAFEHAUS API
<= 1.0.0
Unauthenticated Arbitrary User Password Reset vulnerability
9.8
11 hours ago
ProfileGrid
< 5.9.9.7
Unauthenticated Payment Bypass and Forced Group Membership vulnerability
6.5
11 hours ago
WooCommerce Clover Payment Gateway
< 1.3.6
Unauthenticated Payment Bypass vulnerability
7.5
11 hours ago
Load more