Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,013
Mitigations
Mitigation rules
16,629
No official patch
13,332
In triage
1,039
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
AllCoach
< 1.0.2
Unauthenticated Account Takeover vulnerability
9.8
19 minutes ago
Filter & Grids
< 3.11.3
Unauthenticated Private/Draft Post Disclosure vulnerability
5.3
30 minutes ago
BookingPress
< 1.5.6
Unauthenticated PHP Object Injection vulnerability
9.8
37 minutes ago
ProfilePress
< 4.16.17
Subscriber+ Subscription Cancellation via IDOR vulnerability
4.3
41 minutes ago
WP Support Plus Responsive Ticket System
<= 9.1.2
Unauthenticated SQL Injection via filter[elements] Array Keys vulnerability
9.3
42 minutes ago
Everest Forms
< 3.5.0
Unauthenticated Missing Authorization via Site Assistant REST Endpoints vulnerability
5.3
47 minutes ago
SALESmanago & Leadoo
< 3.11.3
Subscriber+ SQL Injection vulnerability
8.5
48 minutes ago
Royal MCP
< 1.4.26
Subscriber+ Insufficient Authorization in MCP Tools vulnerability
8.1
54 minutes ago
Notifier
< 2.6
Subscriber+ LFI vulnerability
8.8
1 hour ago
Printcart Web to Print Product Designer for WooCommerce
<= 2.8.6
Path Traversal vulnerability
5.3
1 hour ago
Passster
< 4.3.9
Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass vulnerability
5.3
1 hour ago
Charitable
< 1.8.12
Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass vulnerability
5.3
1 hour ago
LitExtension: WooCommerce Migration Plugin
<= 1.2.6
Connector Token Takeover via CSRF vulnerability
4.3
1 hour ago
myCred
< 3.2.5
Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED vulnerability
5.3
1 hour ago
WP Event SOlution
< 4.1.21
Contributor+ Server-Side Request Forgery vulnerability
4.9
1 hour ago
AI Engine
<= 3.6.0
WordPress AI Engine plugin 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools vulnerability
7.2
1 hour ago
Drag and Drop Multiple File Upload – Contact Form 7
< 1.3.9.9
Unauthenticated RCE via Control Character Filename Bypass vulnerability
8.1
1 hour ago
Duplicate Post
< 1.5.6
Authenticated Arbitrary Post Content and Password Disclosure vulnerability
4.3
1 hour ago
Duplicate Post
< 1.5.6
Author+ Password-Protected Post Content Disclosure vulnerability
2.7
1 hour ago
Media LIbrary Assistant
< 3.40
Author+ SQL Injection via mla_search_connector vulnerability
8.5
1 hour ago
Load more