Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
677
Critical
2541
High
5469
Medium
0
Subscribers
10551 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
—
WP 2FA – Two-factor authentication for WordPress [wp-2fa] < 4.1.0
UNKNOWN Plugin wp-2fa CVE-2026-103514 Fixed in 4.1.0 Oct 3, 2026
—
Loco Translate [loco-translate] < 2.8.9
UNKNOWN Plugin loco-translate CVE-2026-94238 Fixed in 2.8.9 Oct 3, 2026
—
Loco Translate [loco-translate] < 2.8.9
UNKNOWN Plugin loco-translate CVE-2026-94239 Fixed in 2.8.9 Oct 3, 2026
—
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] >= 2.2.1 - < 4.3.1
UNKNOWN Plugin metform CVE-2026-86834 Fixed in 4.3.1 Oct 3, 2026
—
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 4.3.1
UNKNOWN Plugin metform CVE-2026-86832 Fixed in 4.3.1 Oct 3, 2026
2.7
SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions
LOW Plugin sms-alert CVE-2026-94258 Fixed in 4.0.1 Oct 8, 2026
2.7
LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
LOW Plugin appointment-booking-plugin CVE-2026-105197 Fixed in 5.6.5 Oct 8, 2026
3.3
LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
LOW Plugin appointment-booking-plugin CVE-2026-105196 Fixed in 5.6.9 Oct 8, 2026
2.7
Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
LOW Plugin booking-calendar CVE-2026-105195 Fixed in 11.8.3 Oct 8, 2026
2.7
Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Image Modification and Post Meta Update via IDOR
LOW Plugin image-photo-gallery-final-tiles-grid CVE-2026-104645 Fixed in 3.6.14 Oct 8, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner