WP Plugin Vulnerability Dashboard

Monitor WordPress plugin security risks across the ecosystem

Total Plugins
23,175
With Vulns
3,430
Unauth Exploits
903
Critical Unpatched
360
Abandoned
827
Avg Risk Score
8.1
CVEs Tracked
13,647
Exploitation Events
133
Intel Posts
1,636
Exploited Plugins
52

Top 5 At-Risk Plugins

Recent Exploitation Events

critical0-DAYRecently
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

7/19/2026
critical0-DAYInvesti
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

7/19/2026
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires

7/15/2026

Latest Security Intelligence

Wordfence
Critical Unauthenticated RCE Vulnerability Discovered in WordPress CoreOriginal source

wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who's affected, the exploitation timeline, and what to do now. The post wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade appeared first on Wordfence.

7/20/2026
darkreading
WordPress Under Siege: Exploiting Newly Discovered Vulnerabilities for Remote TakeoversOriginal source

Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

7/20/2026
hackernews
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a

7/20/2026
hackernews
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks

7/20/2026
securityweekExploitation
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.

7/20/2026