Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
715
Critical
2705
High
5656
Medium
0
Subscribers
10975 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
—
Code Snippets [code-snippets] < 3.10.0
UNKNOWN Plugin code-snippets CVE-2026-106095 Fixed in 3.10.0 Oct 9, 2026
—
Code Snippets [code-snippets] < 3.10.0
UNKNOWN Plugin code-snippets CVE-2026-106097 Fixed in 3.10.0 Oct 9, 2026
—
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 5.7.7
UNKNOWN Plugin backwpup CVE-2026-86826 Fixed in 5.7.7 Oct 8, 2026
—
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 5.7.7
UNKNOWN Plugin backwpup CVE-2026-86828 Fixed in 5.7.7 Oct 8, 2026
—
BackWPup – WordPress Backup & Restore Plugin [backwpup] >= 3.3 - < 5.7.7
UNKNOWN Plugin backwpup CVE-2026-86827 Fixed in 5.7.7 Oct 8, 2026
2.7
Dokan < 5.2.0 - Vendor+ Cross-Vendor Commission Settings Disclosure via Commission REST Endpoint
LOW Plugin dokan-ai-powered-woocommerce-multivendor-marketplace-solution CVE-2026-107694 Fixed in 5.2.0 Oct 11, 2026
2.7
Squadeno < 1.12.0 - Trainer+ Section and Age Group Reassignment via Quick Edit
LOW Plugin squadeno CVE-2026-107507 Fixed in 1.12.0 Oct 11, 2026
2.7
Envira Gallery < 1.16.2 - Author+ IDOR via Shortcode
LOW Plugin envira-gallery CVE-2026-104684 Fixed in 1.16.2 Oct 11, 2026
2.7
Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route
LOW Plugin envira-gallery CVE-2026-104682 Fixed in 1.16.2 Oct 11, 2026
2.7
Envira Gallery < 1.16.2 - Author+ Non-Public Post Title and Excerpt Disclosure via Gallery REST Field
LOW Plugin envira-gallery CVE-2026-104681 Fixed in 1.16.2 Oct 11, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner