Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
663
Critical
2436
High
5208
Medium
0
Subscribers
10126 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
—
Download Manager [download-manager] < 7.5.6
UNKNOWN Plugin download-manager CVE-2026-86609 Fixed in 7.5.6 Sep 27, 2026
—
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] >= 1.23.8 - < 1.26.8
UNKNOWN Plugin updraftplus CVE-2026-82841 Fixed in 1.26.8 Sep 27, 2026
3.1
Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured
LOW Plugin motors CVE-2026-91023 Fixed in 1.4.124 Oct 2, 2026
3.1
EUVD-2026-91247 (CVE-2026-102002) — The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE pl…
LOW Plugin CVE-2026-102002 Oct 2, 2026
3.1
EUVD-2026-91194 (CVE-2026-91023) — The Motors WordPress plugin before 1.4.124 does not properly verify that a use…
LOW Plugin CVE-2026-91023 Oct 2, 2026
3.1
If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name
LOW Plugin if-so-dynamic-content CVE-2026-87973 Fixed in 1.10.2 Oct 1, 2026
3.1
CVE-2026-87973 — The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before
LOW Plugin CVE-2026-87973 Oct 1, 2026
3.1
EUVD-2026-90513 (CVE-2026-87973) — The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a c…
LOW Plugin CVE-2026-87973 Oct 1, 2026
2.7
WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability
LOW Theme astra-wordpress-theme CVE-2026-27085 Sep 30, 2026
2.7
CVE-2026-27085 — Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
LOW Theme CVE-2026-27085 Sep 30, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner