Live Database
WordPress Vulnerability
Database
Real-time security intelligence for the entire WordPress ecosystem: track verified vulnerabilities across plugins, themes, and core.
Threat Distribution
40,078 reportsCritical2,7657%
High8,09420%
Medium29,05973%
Low1600.4%
Filters
None active
Asset Type
Risk Level
Date Range (Last)
Vulnerability Records
40,078 records
Showing 1–10 of 40,078 reports
What is the WordSec vulnerability database?
The WordSec vulnerability database is a public record of security issues disclosed in WordPress plugins, themes and core releases. Each entry states the CVE identifier where one has been assigned, the CVSS base score and severity band, the CWE weakness class, the affected version range, the version that fixed it, the disclosure date and the researcher credited with finding it. Affected ranges use half-open notation, so [4.0, 4.2) means every build from 4.0 up to but not including 4.2.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C