The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total46,759
Mitigations15,163
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
LatePoint<= 5.5.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
LatePoint<= 5.5.0
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
9 hours ago
LatePoint<= 5.5.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
All-in-One WP Migration Unlimited Extension<= 2.83
Missing Authorization to Authenticated (Subscriber+) Arbitrary Backup Schedule Creation and Backup File Download vulnerability
6.5
11 hours ago
Betheme<= 28.4
Authenticated (Author+) Arbitrary File Upload to Remote Code Execution vulnerability
9.1
11 hours ago
ElementsKit Elementor addons Lite<= 3.8.2
Missing Authorization to Unauthenticated Widget Content Overwrite vulnerability
6.5
14 hours ago
Royal Elementor Addons<= 1.7.1056
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
14 hours ago
Blog Settings<= 1.0
Reflected Cross-Site Scripting vulnerability
7.1
14 hours ago
Zingaya Click-to-Call<= 1.0
Reflected Cross-Site Scripting vulnerability
7.1
14 hours ago
NEX-Forms<= 9.1.11
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
14 hours ago
Quiz Maker<= 6.7.1.29
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
15 hours ago
Brizy<= 2.8.11
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
15 hours ago
PixelYourSite PRO<= 12.5.0.1
Unauthenticated Blind Server-Side Request Forgery vulnerability
7.2
15 hours ago
Widget Options - Extended<= 5.3.2
WordPress Widget Options - Extended plugin <= 5.3.2 - Authenticated (Contributor+) Remote Code Execution vulnerability
8.8
15 hours ago
Gravity Forms Bookings premium<= 2.5.9
Unauthenticated SQL Injection vulnerability
9.3
15 hours ago
FluentForm<= 6.2.1
Authenticated (Administrator+) Arbitrary File Read vulnerability
4.9
1 day ago
SliceWP<= 1.2.7
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
1 day ago
Paid Memberships Pro<= 3.6.5
Missing Authorization to Authenticated (Subscriber+) Stripe Webhook Deletion and Payment Processing Disruption vulnerability
7.1
1 day ago
Form Maker by 10Web<= 1.15.42
Unauthenticated SQL Injection vulnerability
9.3
1 day ago
Forminator<= 1.52.1
Unauthenticated Arbitrary File Read vulnerability
7.5
1 day ago