Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
634
Critical
2243
High
4743
Medium
0
Subscribers
9322 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
3.7
MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure
LOW Plugin mpcx-lightbox CVE-2026-87848 Sep 23, 2026
3.7
EUVD-2026-85193 (CVE-2026-87848) — The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any author…
LOW Plugin CVE-2026-87848 Sep 23, 2026
3.7
NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page
LOW Plugin np-quote-request-for-woocommerce CVE-2026-93528 Fixed in 2.4.16 Sep 23, 2026
3.3
WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure
LOW Plugin wc-fields-factory CVE-2026-93507 Fixed in 4.1.11 Sep 23, 2026
2.7
Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list
LOW Plugin event-booking-manager-for-woocommerce CVE-2026-91077 Fixed in 5.7.3 Sep 23, 2026
3.7
Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment
LOW Plugin paid-membership-subscriptions CVE-2026-90951 Fixed in 3.1.0 Sep 23, 2026
3.7
Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link
LOW Plugin forminator-forms CVE-2026-87074 Fixed in 1.57.2.1 Sep 23, 2026
3.1
Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe
LOW Plugin forminator-forms CVE-2026-87069 Fixed in 1.57.2.1 Sep 23, 2026
2.7
The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API
LOW Plugin the-events-calendar CVE-2026-84742 Fixed in 6.17.5 Sep 23, 2026
3.8
The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
LOW Plugin the-events-calendar CVE-2026-84743 Fixed in 6.17.5 Sep 23, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner