WP Plugin Vulnerability Dashboard

Monitor WordPress plugin security risks across the ecosystem

Total Plugins
18,051
With Vulns
3,430
Unauth Exploits
903
Critical Unpatched
360
Abandoned
795
Avg Risk Score
8.8
CVEs Tracked
13,647
Exploitation Events
98
Intel Posts
1,155
Exploited Plugins
42

Top 5 At-Risk Plugins

Recent Exploitation Events

criticalRedirect
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.

~1,000 sites affected
6/2/2026
criticalTraffic
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.

~1,000 sites affected
6/2/2026
Unauthenticated Privilege Escalation Vulnerability Patched in Kirki WordPress Plugin

On May 4th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in the Kirki WordPress plugin. Although the plugin has more than 500,000 active installations, we estimate that only around 150,000 sites are using a vulnerable version, as the issue was introduced in the 6.0 major release. This vulnerability makes it possible for unauthenticated attackers to take over arbitrary user accounts on the site, including administrator accounts, by leveraging the plugin's password reset functionality to have the… The post Unauthenticated Privilege Escalation Vulnerability Patched in Kirki WordPress Plugin appeared first on Wordfence.

~150,000 sites affected
6/1/2026

Latest Security Intelligence

hackernews
Combatting Cyber Threats: Lessons for WordPress Security from AI Model VulnerabilitiesOriginal source

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool's ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress. CVE-2026-33829 refers to a spoofing vulnerability that could expose

6/3/2026
infosecurity
Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws

The emergence of AI models capable to autonomously find and fix vulnerabilities at scale is having a significant impact on patching management, experts say

6/3/2026
hackernews
New HTTP/2 Bomb Threat: Protect Your WordPress Sites from Remote DoS AttacksOriginal source

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb by Calif. "The vulnerable behavior exists in each server's default HTTP/2 configuration," the company said, adding it was discovered by OpenAI Codex by chaining

6/3/2026
bleepingcomputerExploitation
Protecting Your WordPress Site from GitHub Token Theft: Lessons from the VS Code Zero-DayOriginal source

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. [...]

6/3/2026
bleepingcomputer
Critical Kirki flaw exploited to hijack WordPress admin accounts

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]

6/2/2026