Sources and licenses
Where the vulnerability data on this site comes from, and the terms it is published under. Some sources require their copyright notice and license text to be reproduced in full.
Data that requires attribution
The license texts below are reproduced verbatim, not summarized. Reproducing them in full is a condition of the license.
Defiant, Inc. (Wordfence Intelligence)
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you, include a hyperlink to this vulnerability record, and reproduce Defiant's copyright designation and this license in any such copy.
The MITRE Corporation (CVE®)
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
On linking to individual vulnerability records
Defiant's license requires a hyperlink to the vulnerability record wherever the data is reproduced. Each entry on this site links to the record at its source.
Other sources
| Source | Use and terms |
|---|---|
| NVD (NIST National Vulnerability Database) | A work of the U.S. government and in the public domain. Used with attribution. NIST does not endorse this site, and this site is not affiliated with NIST. |
| CISA KEV (Known Exploited Vulnerabilities Catalog) | Published by CISA (USA) and free to use. |
| EPSS (Exploit Prediction Scoring System) | Published by FIRST.org. Free for commercial and non-commercial use, with attribution. |
| WordPress.org API | Used for plugin and theme metadata (name, version, active installs, last updated). |
| WPVulnerability | Used for vulnerabilities in WordPress core. |
Relationship to these organizations
This site is not affiliated with, endorsed by, or sponsored by any of the organizations above. Any error here is ours, not theirs — please do not contact them about this site.
If you spot an error in the data, please tell us through the contact form .