WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts

When a vulnerability is disclosed in a widely used plugin or theme, this page explains what it means and what to do about it. Updated daily.

An entry is listed when it affects 10,000 or more sites, or is estimated likely to be exploited (EPSS 1% or higher), or is known to be exploited (listed in the CISA KEV catalog).

Subscribe via RSS