Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,072
Mitigations
Mitigation rules
16,167
No official patch
13,193
In triage
1,099
Published soon
24
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
ghost
>= 5.46.1, < 6.21.2
NPM: Ghost Content API filter bypass reveals private fields
5.3
32 minutes ago
ghost
>= 4.9.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Feature Image Captions
4.3
35 minutes ago
ghost
>= 6.26.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery Mitigation Issue
4
38 minutes ago
Instagram Feed
<= 6.11.3
Reflected Cross-Site Scripting vulnerability
7.1
2 hours ago
Dokan
<=5.0.2-<=5.0.2
Missing Authorization to Authenticated (Vendor+) Privilege Escalation vulnerability
8.8
2 hours ago
Points and Rewards for WooCommerce
< 2.10.1
Unauthenticated Arbitrary User Wallet & Points Manipulation vulnerability
5.9
2 hours ago
VikRentItems Flexible Rental Management System
<= 1.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Advanced Views
<= 3.9.1
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
6.5
2 hours ago
Udimi Tools
<= 3.2
Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset vulnerability
6.5
2 hours ago
Layouts for WPBakery
<= 1.1.3
Missing Authorization to Unauthenticated Template Cache Manipulation vulnerability
6.5
2 hours ago
Seraphinite Accelerator
<= 2.29.18
Reflected Cross-Site Scripting vulnerability
6.1
2 hours ago
WP Travel Engine
< 6.8.2
Unauthenticated Trip Difficulty Level Option Update vulnerability
6.5
3 hours ago
Frontend Admin by DynamiApps
< 3.29.7
Subscriber+ Taxonomy Term Creation/Modification/Deletion vulnerability
6.5
3 hours ago
FluentForm
<= 6.2.8
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
WP Real IP-based Access Control
<= 1.3.1
Unauthenticated Stored XSS vulnerability
7.1
3 hours ago
Thumbnail carousel slider
< 1.1.53
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
MailChimp Subscribe Forms
<= 4.3.3
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
Netroics Blog Posts Grid
<= 1.0
Authenticated (Editor+) Stored Cross-Site Scripting vulnerability
6.5
4 hours ago
Subscriptions for WooCommerce
<= 2.0.0
Authenticated (Contributor+) Privilege Escalation vulnerability
8.8
4 hours ago
Easy Property Listings
<= 3.5.24
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
5 hours ago
Load more