Pricing
Case studies
Login
Start trial
Ananda Dhakal (Patchstack)
Say thanks
0.00
XP
0
Reports
16
Reports, last 90 days
-
21 Sep, 2026
🇳🇵
Lvl 0
0
0
0
0
Website
X
GitHub
Sort by
Priority
Severity
Exploited
Search
Clear
Affected software | Vulnerability
CVE
AXP
Severity
Reported
PropertyHive
<= 2.2.6
Cross Site Scripting (XSS)
N/A
6.5
11/09/2026
WP Maps
<= 4.9.9
SQL Injection
N/A
7.6
08/09/2026
Newsletters
<= 4.18
SQL Injection
N/A
7.6
08/09/2026
WPMasterToolKit
<= 2.22.0
SQL Injection
N/A
7.6
08/09/2026
WC Vendors Marketplace
<= 2.7.2.1
SQL Injection
N/A
7.6
08/09/2026
SKT Addons for Elementor
<= 4.0
SQL Injection
N/A
7.6
08/09/2026
WP-Lister Lite for eBay
<= 3.8.11
SQL Injection
N/A
7.6
08/09/2026
PublishPress Series
<= 3.1.3
SQL Injection
N/A
7.6
08/09/2026
MC Woocommerce Wishlist
<= 1.9.21
SQL Injection
N/A
7.6
08/09/2026
Simple Membership
<= 4.8.2
Broken Access Control
N/A
5.3
03/09/2026
Booking Calendar
<= 11.7
Broken Access Control
21.2
5.3
03/09/2026
WP Mega Menu
<= 1.4.2
SQL Injection
N/A
7.6
08/09/2026
Migratico Lite
<= 2.6.8
Remote Code Execution (RCE)
N/A
10
28/08/2026
bbPress
<= 2.6.14
Sensitive Data Exposure
42.4
5.3
25/08/2026
Sky Addons for Elementor
<= 3.8.4
SQL Injection
N/A
7.6
08/09/2026
Amelia
<= 2.4.9
SQL Injection
N/A
7.6
03/09/2026
Starter Templates
<= 4.7.5
Insecure Direct Object References (IDOR)
25.96
4.3
28/08/2026
Site Kit by Google
<= 1.186.0
Cross Site Request Forgery (CSRF)
21.5
4.3
20/08/2026
ZHBackup – Backup, Restore & Migration
<= 2.4.2
Sensitive Data Exposure
N/A
7.5
28/08/2026
SiteSkite
<= 2.1.5
Privilege Escalation
N/A
8.1
28/08/2026
Simple Cloudflare Turnstile
<= 1.42.1
Bypass Vulnerability
64.4
5.6
28/08/2026
Hide My WP Ghost
<= 7.0.09
Server Side Request Forgery (SSRF)
57.6
7.2
28/08/2026
WooCommerce
< 11.1.0
Denial of Service Attack
150
7.5
20/08/2026
WooCommerce
<= 10.9.4
SQL Injection
N/A
7.6
04/09/2026
KP Agent Ready
<= 1.1.99
Sensitive Data Exposure
N/A
5.3
28/08/2026
MountDev AI MCP Connector for WordPress
<= 1.6.5
Broken Access Control
N/A
6.5
28/08/2026
Agentimus – AI SEO, llms.txt & MCP for AI Agents
<= 1.51.0
Broken Access Control
N/A
8.1
28/08/2026
FluentBooking Pro
<= 2.2.1
Bypass Vulnerability
N/A
5.9
13/08/2026
Migrate Guru – Site Migration & Cloning
<= 6.65
Denial of Service Attack
75
7.5
28/08/2026
MalCare Security
<= 6.69
Denial of Service Attack
75
7.5
28/08/2026
Really Simple SSL
<= 9.8.0
Broken Authentication
118.4
7.4
20/08/2026
Really Simple SSL
<= 9.8.0
Denial of Service Attack
84.8
5.3
28/08/2026
Broken Link Checker
<= 2.4.14
Server Side Request Forgery (SSRF)
N/A
5.5
25/08/2026
WCFM Marketplace
<= 3.8.2
Cross Site Scripting (XSS)
5.61
6.5
13/07/2026
bbPress
<= 2.6.14
Broken Access Control
42.4
5.3
16/07/2026
Fluent Forms Pro Add On Pack
<= 6.2.12
Broken Access Control
11.25
7.5
13/08/2026
Fluent Forms Pro Add On Pack
<= 6.2.12
Privilege Escalation
16.88
7.5
13/08/2026
SiteGround Security
<= 1.6.6
Bypass Vulnerability
113.4
8.1
25/08/2026
WordPress Social Login and Register
<= 7.8.2
Cross Site Scripting (XSS)
16.33
7.1
25/08/2026
Rank Math SEO
<= 1.0.276
Remote Code Execution (RCE)
N/A
7.2
20/08/2026
ACF Extended
<= 0.9.2.6
Broken Access Control
N/A
4.3
04/06/2026
FluentBooking Pro
<= 2.2.4
Cross Site Request Forgery (CSRF)
N/A
8.1
13/08/2026
FluentPlayer Pro
<= 1.3.2
Broken Access Control
N/A
4.9
13/08/2026
Fluent Boards Pro
<= 2.0.11
PHP Object Injection
N/A
7.2
13/08/2026
Fluent Boards Pro
<= 2.0.11
Arbitrary File Deletion
N/A
6.8
13/08/2026
Fluent Boards Pro
<= 2.0.11
Arbitrary File Upload
N/A
9.1
13/08/2026
Fluent Boards Pro
<= 2.0.11
Cross Site Scripting (XSS)
N/A
6.5
13/08/2026
FluentCRM Pro
<= 3.1.12
Privilege Escalation
N/A
7.2
13/08/2026
Fluent Support Pro
<= 2.3.1
Cross Site Request Forgery (CSRF)
N/A
5.4
13/08/2026
Fluent Boards Pro
<= 2.0.11
Insecure Direct Object References (IDOR)
N/A
5.3
13/08/2026
FluentCRM Pro
<= 3.1.12
Server Side Request Forgery (SSRF)
N/A
4.9
13/08/2026
Fluent Support Pro
<= 2.3.1
Broken Access Control
N/A
5.4
13/08/2026
FluentCRM Pro
<= 3.1.12
SQL Injection
N/A
7.6
13/08/2026
WP Cafe Pro
< 3.0.15
Sensitive Data Exposure
N/A
7.5
01/07/2026
InfiniteWP Client
<= 1.13.9
SQL Injection
N/A
7.6
16/07/2026
WP Cafe Pro
< 3.0.15
Local File Inclusion
N/A
9.8
01/07/2026
WP Cafe Pro
< 3.0.15
Local File Inclusion
N/A
6.6
01/07/2026
OptionTree
<= 2.7.3
PHP Object Injection
N/A
7.2
06/07/2026
Slider by 10Web
<= 1.2.62
Cross Site Request Forgery (CSRF)
3.7
7.4
09/07/2026
Wise Chat
<= 3.4.1
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
Featured Video Plus
<= 2.3.3
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
Charitable
<= 1.8.11.3
Broken Access Control
15
7.5
09/07/2026
Frontend Admin by DynamiApps
<= 3.29.10
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
WPZOOM Forms – Contact Form Plugin for Gutenberg
<= 2.0.7
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
Login With Ajax
<= 4.5.1
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
Video Conferencing with Zoom
<= 4.6.9
Cross Site Scripting (XSS)
N/A
6.5
09/07/2026
Wufoo Shortcode
<= 1.55
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
Typing Effect
<= 1.3.7
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
Table Of Contents Block
<= 1.5.0
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
WP Tab Widget
<= 1.2.11
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
GeoDirectory
<= 2.8.177
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
RomethemeForm For Elementor
<= 1.2.7
Broken Access Control
N/A
4.3
14/07/2026
Gravity Booster – Styles & Layouts for Gravity Forms
<= 6.1
Broken Access Control
10.8
5.4
14/07/2026
WP Table Builder
<= 2.2.0
Broken Access Control
N/A
4.3
16/07/2026
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery
<= 1.16.20
Sensitive Data Exposure
31.8
5.3
16/07/2026
Shortcodes and extra features for Phlox theme
<= 2.17.22
Sensitive Data Exposure
31.8
5.3
16/07/2026
Razorpay for WooCommerce
<= 4.8.7
Insecure Direct Object References (IDOR)
42.4
5.3
16/07/2026
MailChimp For WooCommerce
< 6.2
SQL Injection
N/A
7.6
16/07/2026
WP Data Access
<= 5.5.79
Cross Site Scripting (XSS)
N/A
5.9
13/07/2026
Gutenverse Companion
<= 2.5.1
Server Side Request Forgery (SSRF)
10.8
7.2
09/07/2026
Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
<= 1.0.7
Broken Access Control
N/A
7.5
09/07/2026
Advanced Custom Fields: Font Awesome Field
<= 6.1.2
Broken Access Control
N/A
4.3
06/07/2026
Theme My Login
<= 7.1.14
Cross Site Request Forgery (CSRF)
6.45
4.3
06/07/2026
Custom CSS and JavaScript
<= 2.0.16
Sensitive Data Exposure
10.6
5.3
08/07/2026
Export Import Menus
<= 1.9.2
Sensitive Data Exposure
10.6
5.3
08/07/2026
Featured Video Plus
<= 2.3.3
Sensitive Data Exposure
10.6
5.3
08/07/2026
Plugins Garbage Collector (Database Cleanup)
<= 0.14
Cross Site Request Forgery (CSRF)
3.25
6.5
08/07/2026
Subscribe to Comments
<= 2.3.1
Cross Site Scripting (XSS)
N/A
5.9
08/07/2026
Polylang Pro
<= 3.8.5
Sensitive Data Exposure
N/A
4.3
No date
WPBruiser {no- Captcha anti-Spam}
<= 3.1.43
PHP Object Injection
19.6
9.8
09/07/2026
Order Delivery Date for WooCommerce
<= 4.6.0
Privilege Escalation
N/A
7.2
09/07/2026
Simple Membership
<= 4.7.8
Broken Access Control
30
7.5
14/07/2026
Mercado Pago payments for WooCommerce
<= 8.9.0
Insecure Direct Object References (IDOR)
42.4
5.3
16/07/2026
FiboSearch
<= 1.33.0
Cross Site Scripting (XSS)
N/A
5.9
16/07/2026
Powerkit
<= 3.1.0
Cross Site Scripting (XSS)
N/A
6.5
13/07/2026
Advanced AJAX Product Filters
<= 3.2.0.3
Cross Site Scripting (XSS)
42.6
7.1
14/07/2026
JetFormBuilder
<= 3.6.4.1
Broken Access Control
51.75
7.5
02/07/2026
ShopLentor Pro
<= 2.8.5
Broken Access Control
7.95
5.3
01/07/2026
ShopLentor Pro
<= 2.8.5
Broken Access Control
3.22
4.3
01/07/2026
JetSearch
<= 3.6.1.2
Sensitive Data Exposure
12.19
5.3
02/07/2026
1
2
3
4
Report vulnerabilities to earn bounties and rewards!
Read more
Include pending
Back to top