Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
620
Critical
2176
High
4551
Medium
0
Subscribers
9050 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption
UNKNOWN Plugin tiktok CVE-2026-92965 Fixed in 1.4.2 Sep 20, 2026
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users
UNKNOWN Plugin import-and-export-users-and-customers CVE-2026-92540 Fixed in 2.5.2 Sep 20, 2026
Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts
UNKNOWN Plugin meow-gallery CVE-2026-92423 Fixed in 5.5.5 Sep 20, 2026
Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route
UNKNOWN Plugin meow-gallery CVE-2026-92422 Fixed in 5.5.5 Sep 20, 2026
Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF
UNKNOWN Plugin sign-up-sheets CVE-2026-92410 Fixed in 2.4.0 Sep 20, 2026
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer
UNKNOWN Plugin import-and-export-users-and-customers CVE-2026-92541 Fixed in 2.5.2 Sep 20, 2026
Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
UNKNOWN Plugin forminator-forms CVE-2026-87068 Fixed in 1.57.2.1 Sep 20, 2026
Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection
UNKNOWN Plugin forminator-forms CVE-2026-87067 Fixed in 1.57.2.1 Sep 20, 2026
Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering
UNKNOWN Plugin tripzzy CVE-2026-87840 Fixed in 1.5.1 Sep 20, 2026
Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion
UNKNOWN Plugin tripzzy CVE-2026-87839 Fixed in 1.5.1 Sep 20, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner