Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,161
Mitigations
Mitigation rules
16,140
No official patch
13,202
In triage
1,139
Published soon
11
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@apostrophecms/seo
<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
3 hours ago
apostrophe
<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
3 hours ago
@nocobase/plugin-notification-in-app-message
<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
6 hours ago
jodit
< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
6 hours ago
@phun-ky/defaults-deep
< 2.0.5
NPM: @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
7.3
7 hours ago
hashi-vault-js
<= 0.5.1
NPM: hashi-vault-js has a path traversal and query parameter injection
8.7
8 hours ago
dssrf
<= 1.0.4
NPM: dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
8.7
8 hours ago
@dynatrace-oss/dynatrace-mcp-server
<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
9 hours ago
Simply Poll
<= 1.4.1
Unauthenticated SQL Injection vulnerability
9.3
16 hours ago
Meta Box AIO
<= 3.8.0
Missing Authorization to Unauthenticated Arbitrary Post Deletion vulnerability
9.1
16 hours ago
WP Fast Total Search
<= 1.80.280
Unauthenticated SQL Injection vulnerability
9.3
16 hours ago
Plugin Organizer
<= 10.2.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
16 hours ago
Fluent Forms Pro Add On Pack
<= 6.2.6
Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change vulnerability
8.8
16 hours ago
WPDM – Premium Packages
<= 6.2.0
Unauthenticated SQL Injection vulnerability
9.3
17 hours ago
TrueBooker
<= 1.2.2
Unauthenticated SQL Injection vulnerability
9.3
17 hours ago
Taskbuilder
<= 5.0.9
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
17 hours ago
Web Directory Free
<= 1.7.13
Unauthenticated SQL Injection vulnerability
9.3
18 hours ago
Demi – One Click Demo Import, Backup & Site Migration
<= 0.0.7
Unauthenticated Arbitrary Directory Deletion vulnerability
7.5
18 hours ago
Customer Switching
< 2.1.3
Customer+ Privilege Escalation to Administrator vulnerability
8.8
18 hours ago
@aws-amplify/codegen-ui-react
<= 2.20.2
NPM: AWS Amplify Studio UI Component Properties Has an Input Validation Issue
9.5
1 day ago
Load more