The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total36,615
Mitigations13,450
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Client Testimonial Slider<= 2.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'aft_testimonial_meta_name' Metabox Field vulnerability
6.5
11 minutes ago
Contact Form vCard Generator<= 2.4
Missing Authorization to Unauthenticated Sensitive Information Exposure via 'wp-gvc-cf-download-id' Parameter vulnerability
5.3
12 minutes ago
Debt.com Business in a Box<= 4.1.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
13 minutes ago
Menu Card<= 0.8.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
16 minutes ago
Entry Views<= 1.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
6.5
16 minutes ago
Curved Text<= 0.1
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
17 minutes ago
Header and Footer Scripts<= 2.2.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
18 minutes ago
The Tooltip<= 1.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
19 minutes ago
WP Popup Magic<= 1.0.0
Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute vulnerability
6.5
20 minutes ago
Nearby Now Reviews<= 5.2
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
6.5
21 minutes ago
AMP for WP<= 1.1.10
Authenticated Stored Cross-Site Scripting via SVG File Upload vulnerability
5.9
23 minutes ago
Booking Calendar<= 10.14.10
Unauthenticated Sensitive Information Exposure vulnerability
5.3
24 minutes ago
Tutor LMS<= 3.9.3
WordPress Tutor LMS - eLearning and online course solution plugin <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification vulnerability
5.4
25 minutes ago
WP Table Builder<= 2.0.19
Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation vulnerability
5.4
26 minutes ago
Tutor LMS<= 3.9.3
WordPress Tutor LMS - eLearning and online course solution plugin <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass vulnerability
4.3
33 minutes ago
WP Google Street View<= 1.1.8
Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpgsv_map' Shortcode vulnerability
6.5
40 minutes ago
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimization (image SEO) + Woocommerce<= 2.2.1
WordPress BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
41 minutes ago
BetterDocs<= 4.3.3
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
6.5
42 minutes ago
IndieWeb<= 4.0.5
Authenticated (Author+) Stored Cross-Site Scripting via 'Telephone' Parameter vulnerability
5.9
43 minutes ago
Forminator<= 1.49.1
Missing Authorization to Authenticated (Forminator User+) CSV Export vulnerability
5.3
46 minutes ago