Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
665
Critical
2490
High
5341
Medium
0
Subscribers
10338 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
—
WP 2FA – Two-factor authentication for WordPress [wp-2fa] < 4.1.0
UNKNOWN Plugin wp-2fa CVE-2026-103514 Fixed in 4.1.0 Oct 3, 2026
—
Download Manager [download-manager] < 3.3.71
UNKNOWN Plugin download-manager CVE-2026-86610 Fixed in 3.3.71 Oct 1, 2026
—
Cache Enabler [cache-enabler] < 1.8.17
UNKNOWN Plugin cache-enabler CVE-2026-19253 Fixed in 1.8.17 Oct 1, 2026
—
EWWW Image Optimizer [ewww-image-optimizer] >= 8.6.0 - < 8.8.0
UNKNOWN Plugin ewww-image-optimizer CVE-2026-91051 Fixed in 8.8.0 Sep 30, 2026
—
EWWW Image Optimizer [ewww-image-optimizer] < 8.8.0
UNKNOWN Plugin ewww-image-optimizer CVE-2026-91072 Fixed in 8.8.0 Sep 30, 2026
—
Media Library Organizer – Folders, File Manager & Media Categories [media-library-organizer] >= 2.0.4 - < 2.1.4
UNKNOWN Plugin media-library-organizer CVE-2026-94297 Fixed in 2.1.4 Sep 30, 2026
3.5
Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials
LOW Plugin simple-shopping-cart CVE-2026-104119 Fixed in 5.2.6 Oct 4, 2026
3.5
CVE-2026-104119 — The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field va
LOW Plugin CVE-2026-104119 Oct 4, 2026
3.5
EUVD-2026-92073 (CVE-2026-104119) — The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of …
LOW Plugin CVE-2026-104119 Oct 4, 2026
3.7
Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code
LOW Plugin pie-register CVE-2026-96962 Fixed in 3.8.4.14 Oct 3, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner