Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,171
Mitigations
Mitigation rules
17,052
No official patch
13,345
In triage
1,284
Published soon
5
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@zereight/mcp-gitlab
>= 0.0.1, < 2.1.27
NPM: @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
9.6
13 hours ago
@zereight/mcp-gitlab
< 2.1.30
NPM: @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
9.6
13 hours ago
@zereight/mcp-gitlab
< 2.1.30
NPM: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
8.1
13 hours ago
Admin Menu Editor Pro
2.35-2.36
Backdoor vulnerability
10
16 hours ago
JetFormBuilder
<= 3.6.2
Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter
9.8
18 hours ago
Contest Gallery
<= 32.0.1
Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter vulnerability
8.8
18 hours ago
TrueBooker
<= 1.2.3
Privilege Escalation vulnerability
9.8
18 hours ago
Consulting
<= 6.7.16
WordPress Consulting - Business, Finance WordPress Theme theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation vulnerability
9.8
1 day ago
Advanced Custom Fields: Extended PRO
<= 0.9.2.6
Unauthenticated Remote Code Execution vulnerability
10
1 day ago
WP Event Solution
<= 4.1.23
WordPress Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce plugin <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter vulnerability
7.5
1 day ago
Album Cover Finder
<= 0.7.0
Unauthenticated SQLi vulnerability
9.3
2 days ago
WPStoreCart
<= 5.0.7
Unauthenticated PHP Object Injection vulnerability
9.8
2 days ago
SAMO Forms
<= 1.0.0
Unauthenticated SQLi vulnerability
9.3
2 days ago
Frontegg SAML SSO
<= 1.0.1
Unauthenticated Account Takeover vulnerability
9.8
2 days ago
Zonify – Amazon Product Importer for WooCommerce
< 1.0.5
Unauthenticated Account Login Token Disclosure vulnerability
7.5
2 days ago
Code Monkeys Proposals
<= 1.0.1
Subscriber+ Arbitrary File Deletion vulnerability
8.6
2 days ago
Gpx2Graphics
<= 0.3
Arbitrary File Upload vulnerability
10
2 days ago
WebTotem Backups
<= 1.0.1
Subscriber+ Arbitrary File Deletion vulnerability
8.6
2 days ago
DS Ad Rotator
<= 0.8
Unauthenticated Arbitrary File Upload vulnerability
10
2 days ago
CryptoPayment Gateway
1.2.1-1.2.2
Unauthenticated Arbitrary File Deletion and Settings Update vulnerability
8.6
2 days ago
Load more