WordPress Vulnerability Database

The most comprehensive open vulnerability database for WordPress plugins, themes, and server infrastructure.

16,106

plugins with known vulnerabilities

2,198

themes with known vulnerabilities

13,246

vulnerabilities without a fix

1,948

critical severity (score ≥ 9.0)

WPVulnerability

Official WordPress Plugin

WPVulnerability

Real-time vulnerability scanner for your WordPress dashboard. Monitors your core, plugins, themes, PHP, Apache, nginx, MariaDB, MySQL, ImageMagick, curl and more — all in one place.

10,000+Active installs
★★★★★20 reviews
4.3.1Latest version
6.9.4Tested with WP
Install free on WordPress.org →

Notable vulnerabilities — last 90 days

Latest Plugin Vulnerabilities

View all →
Essential Real Estate
Medium 6.5 Unfixed
2025-12-16≤ 5.3.2

WordPress Essential Real Estate plugin <= 5.3.2 - Insecure Direct Object References (IDOR) vulnerability

Latest Theme Vulnerabilities

View all →
Avante
N/A
2026-05-08< 3.0.5

WordPress Avante Theme < 3.0.5 is vulnerable to a medium priority Cross Site Scripting (XSS)

Alone
Critical 9.1
2025-07-15< 7.8.7

Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion

Latest WordPress Core Vulnerabilities

View all →