Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
193
Critical
755
High
1395
Medium
0
Subscribers
2567 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
UNKNOWN Plugin gallery-for-google-photos CVE-2026-15236 Fixed in 1.2.1 Aug 2, 2026
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
UNKNOWN Plugin charitable CVE-2025-15675 Fixed in 1.8.5.3 Aug 2, 2026
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
UNKNOWN Plugin webtoffee-cookie-consent CVE-2026-13389 Fixed in 3.5.3 Aug 2, 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
UNKNOWN Plugin simply-schedule-appointments CVE-2026-16540 Fixed in 1.6.12.6 Aug 2, 2026
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
UNKNOWN Plugin profilegrid CVE-2026-16291 Fixed in 5.9.9.8 Aug 2, 2026
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
UNKNOWN Plugin event-booking-manager-for-woocommerce CVE-2026-16062 Fixed in 5.3.7 Aug 2, 2026
Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
UNKNOWN Plugin event-booking-manager-for-woocommerce CVE-2026-16063 Fixed in 5.3.7 Aug 2, 2026
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
UNKNOWN Plugin event-booking-manager-for-woocommerce CVE-2026-16064 Fixed in 5.3.7 Aug 2, 2026
Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
UNKNOWN Plugin frontend-file-manager-plugin CVE-2026-16292 Aug 2, 2026
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
UNKNOWN Plugin product-attachment-for-woocommerce CVE-2026-16285 Fixed in 2.3.3 Aug 2, 2026

Recently removed from WordPress.org

These plugins were closed/removed from the repository.

🚫
yooessentials
yooessentials

Not found on WordPress.org

Detected: Jul 29, 2026

🚫
WPML Multilingual CMS
sitepress-multilingual-cms

Plugin closed by WordPress.org

Detected: Jul 29, 2026

🚫
Pixel Caffeine
pixel-caffeine

Plugin closed by WordPress.org

Detected: Jul 29, 2026

🚫
Advanced Ads – Ad Manager &amp; AdSense
advanced-ads

Plugin closed by WordPress.org

Detected: Jul 27, 2026

🚫
oxygen
oxygen

Not found on WordPress.org

Detected: Jul 24, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner