Live Database

WordPress Vulnerability
Database

Real-time security intelligence for the entire WordPress ecosystem: track verified vulnerabilities across plugins, themes, and core.

Threat Distribution

40,078 reports
Critical2,7657%
High8,09420%
Medium29,05973%
Low1600.4%

Filters

None active

Asset Type
Risk Level
Date Range (Last)

Vulnerability Records

40,078 records
2026-09-11 18:53CVE-2026-85198
6.5
Medium
Nhien Pham (nhienit) (nhienit)Yes
2026-09-11 18:52CVE-2026-85200
7.5
High
yckYes
2026-09-11 18:49CVE-2026-78175
8.8
High
Chloe ChamberlandYes
2026-09-11 18:48CVE-2026-11355
5.3
Medium
adhikara13Yes
2026-09-11 18:44CVE-2026-16482
7.5
High
Wordfence PRISMYes
2026-09-11 18:42CVE-2026-77161
6.5
Medium
Wordfence PRISMYes
2026-09-11 18:40CVE-2026-78159
9.8
Critical
Chloe ChamberlandYes
2026-09-11 18:39CVE-2026-78006
9.8
Critical
Chloe ChamberlandYes
2026-09-11 00:00CVE-2026-15451
8.8
High
andrea bocchettiYes
2026-09-11 00:00CVE-2026-17585
5.3
Medium
TarPeg007Yes
Showing 1–10 of 40,078 reports

What is the WordSec vulnerability database?

The WordSec vulnerability database is a public record of security issues disclosed in WordPress plugins, themes and core releases. Each entry states the CVE identifier where one has been assigned, the CVSS base score and severity band, the CWE weakness class, the affected version range, the version that fixed it, the disclosure date and the researcher credited with finding it. Affected ranges use half-open notation, so [4.0, 4.2) means every build from 4.0 up to but not including 4.2.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C