Live vulnerability tracking

WordPress security
alerts that matter

Get notified the moment a vulnerability is found in WordPress core, your plugins, or your theme. Free newsletter + personalised alerts for your sites.

Double opt-in · GDPR compliant · Unsubscribe anytime

Security overview Last 7 days
665
Critical
2499
High
5346
Medium
0
Subscribers
10356 total vulnerabilities tracked

Everything you need to stay secure

One platform for all WordPress security intelligence.

🔍
Site Scanner

Scan any WordPress site to detect installed plugins, themes and core version — then instantly check for known vulnerabilities.

📬
Daily Newsletter

Receive a curated daily digest of new WordPress vulnerabilities. Critical issues get their own immediate alert.

🎯
Personalized Alerts

Monitor your specific sites. Get an email only when a vulnerability affects plugins or themes you actually use.

🚫
Closed Plugin Tracker

Track plugins removed from the WordPress.org repository — often a sign of a serious security issue.

🔗
WP Plugin Integration

Install our free WordPress plugin on your site for automatic detection of all installed components — no manual URL entry.

🛡️
GDPR Compliant

Double opt-in, transparent data use, easy one-click unsubscribe. Your data stays in the EU. No tracking.

Latest vulnerabilities

Most recent WordPress security issues from all sources.

Scan your site →
—
Loco Translate [loco-translate] < 2.8.9
UNKNOWN Plugin loco-translate CVE-2026-94238 Fixed in 2.8.9 Oct 3, 2026
—
WP 2FA – Two-factor authentication for WordPress [wp-2fa] < 4.1.0
UNKNOWN Plugin wp-2fa CVE-2026-103514 Fixed in 4.1.0 Oct 3, 2026
—
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 4.3.1
UNKNOWN Plugin metform CVE-2026-86832 Fixed in 4.3.1 Oct 3, 2026
—
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] >= 2.2.1 - < 4.3.1
UNKNOWN Plugin metform CVE-2026-86834 Fixed in 4.3.1 Oct 3, 2026
—
Loco Translate [loco-translate] < 2.8.9
UNKNOWN Plugin loco-translate CVE-2026-94239 Fixed in 2.8.9 Oct 3, 2026
—
Download Manager [download-manager] < 3.3.71
UNKNOWN Plugin download-manager CVE-2026-86610 Fixed in 3.3.71 Oct 1, 2026
—
Cache Enabler [cache-enabler] < 1.8.17
UNKNOWN Plugin cache-enabler CVE-2026-19253 Fixed in 1.8.17 Oct 1, 2026
—
Media Library Organizer – Folders, File Manager & Media Categories [media-library-organizer] >= 2.0.4 - < 2.1.4
UNKNOWN Plugin media-library-organizer CVE-2026-94297 Fixed in 2.1.4 Sep 30, 2026
—
EWWW Image Optimizer [ewww-image-optimizer] >= 8.6.0 - < 8.8.0
UNKNOWN Plugin ewww-image-optimizer CVE-2026-91051 Fixed in 8.8.0 Sep 30, 2026
—
EWWW Image Optimizer [ewww-image-optimizer] < 8.8.0
UNKNOWN Plugin ewww-image-optimizer CVE-2026-91072 Fixed in 8.8.0 Sep 30, 2026

Ready to secure your WordPress sites?

Create a free account to monitor your sites and get personalized vulnerability alerts.

Create free account Try the scanner