Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
665
Critical
2482
High
5293
Medium
0
Subscribers
10272 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
3.7
Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code
LOW Plugin pie-register CVE-2026-96962 Fixed in 3.8.4.14 Oct 3, 2026
3.7
MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integration
LOW Plugin metform CVE-2026-86834 Fixed in 4.3.1 Oct 3, 2026
3.7
WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path
LOW Plugin wp-ultimate-csv-importer CVE-2026-80518 Fixed in 9.2 Oct 3, 2026
3.5
WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload
LOW Plugin wp-ultimate-csv-importer CVE-2026-80517 Fixed in 9.2 Oct 3, 2026
3.7
CVE-2026-96962 — The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code re
LOW Plugin CVE-2026-96962 Oct 3, 2026
3.7
CVE-2026-86834 — The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writ
LOW Plugin CVE-2026-86834 Oct 3, 2026
3.5
CVE-2026-80517 — The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types
LOW Plugin CVE-2026-80517 Oct 3, 2026
3.7
CVE-2026-80518 — The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when d
LOW Plugin CVE-2026-80518 Oct 3, 2026
3.7
EUVD-2026-91949 (CVE-2026-96962) — The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to …
LOW Plugin CVE-2026-96962 Oct 3, 2026
3.7
EUVD-2026-91940 (CVE-2026-86834) — The MetForm WordPress plugin before 4.3.1 does not properly restrict access to…
LOW Plugin CVE-2026-86834 Oct 3, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner