Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
27
Critical
84
High
183
Medium
0
Subscribers
294 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
5.1
WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component
MEDIUM Theme theme-wibar CVE-2020-37235 May 16, 2026
5.1
WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting
MEDIUM Plugin buddypress CVE-2020-37233 May 16, 2026
6.4
CVE-2020-37235 — WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand compon
MEDIUM Theme CVE-2020-37235 May 16, 2026
6.4
CVE-2020-37233 — WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allo
MEDIUM Plugin CVE-2020-37233 May 16, 2026
5.1
EUVD-2021-34825 (CVE-2021-47957) — Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that …
MEDIUM Plugin CVE-2021-47957 May 16, 2026
5.1
EUVD-2020-31237 (CVE-2020-37235) — WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerabilit…
MEDIUM Plugin CVE-2020-37235 May 16, 2026
5.1
EUVD-2020-31235 (CVE-2020-37233) — WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vu…
MEDIUM Plugin CVE-2020-37233 May 16, 2026
4.3
EUVD-2025-209886 (CVE-2025-4202) — The Multicollab: Content Team Collaboration and Editorial Workflow plugin for W…
MEDIUM Plugin CVE-2025-4202 May 16, 2026
5.3
EUVD-2026-30669 (CVE-2026-8681) — The Essential Chat Support plugin for WordPress is vulnerable to authorization …
MEDIUM Plugin CVE-2026-8681 May 16, 2026
4.9
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
MEDIUM Plugin nex-forms-ultimate-forms-plugin-for-wordpress CVE-2026-7046 May 15, 2026

Recently removed from WordPress.org

These plugins were closed/removed from the repository.

🚫
epic-gallery
epic-gallery

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
advanced-ads-tracking
advanced-ads-tracking

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
wp-cli-login-server
wp-cli-login-server

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
wp-alerts-scanner
wp-alerts-scanner

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
voxel-toolkit
voxel-toolkit

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
voxel-calendar
voxel-calendar

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
unlimited-elements-for-elementor-premium
unlimited-elements-for-elementor-premium

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
truelang
truelang

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
publishpress-checklists-pro
publishpress-checklists-pro

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
mailpoet-premium
mailpoet-premium

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
epic-news-element
epic-news-element

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
essential-addons-for-voxel
essential-addons-for-voxel

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
autoupdate
autoupdate

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
advanced-ads-pro
advanced-ads-pro

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
Social Warfare
social-warfare

Security vulnerability

Detected: May 7, 2026

🚫
Captcha
captcha

Guideline violation

Detected: May 7, 2026

🚫
Related Posts For Wp
related-posts-for-wp

Security vulnerability

Detected: May 7, 2026

🚫
Wp Fastest Cache Premium
wp-fastest-cache-premium

Licensing issues

Detected: May 7, 2026

🚫
Display Widgets
display-widgets

Security vulnerability

Detected: May 7, 2026

🚫
bravis-user
bravis-user

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
wp-support-tickets
wp-support-tickets

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
betterdocs-pro
betterdocs-pro

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
bravis-addons
bravis-addons

Plugin removed from WordPress.org

Detected: May 7, 2026

🚫
elementor-pro
elementor-pro

Plugin removed from WordPress.org

Detected: May 7, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner