API Monitor free

State Of WordPress Security In 2021

Read the whitepaper

Vulnerability API

Integrate vulnerability alerts inside of your product with our detailed vulnerability API.

How we do it

We collect data across the web, commits, databases and manage a bounty platform for ethical hackers.

Why open-source

WordPress powers over 40% of all sites, including the White House, Mercedes-Benz… and Beyoncé.

Vulnerability API

Integrate vulnerability alerts inside of your product with our detailed vulnerability API.

How we do it

We collect data across the web, commits, databases and manage a bounty platform for ethical hackers.

Why open-source

WordPress powers over 40% of all sites, including the White House, Mercedes-Benz… and Beyoncé.

Plugin

WordPress Popular Posts

<= 5.5.1

Reflected CrossSite Scripting (XSS) vulnerability

6.1

4 hours ago

Plugin

SP Project & Document Manager

<= 4.57

Sensitive File Disclosure vulnerability

5.3

4 hours ago

Plugin

Exports and Reports

<= 0.9.1

Authenticated CSV Injection vulnerability

5.4

5 hours ago

Plugin

WP Maintenance

<= 6.0.7

Authenticated Stored CrossSite Scripting (XSS) vulnerability

3.4

1 day ago

Plugin

Custom Product Tabs for WooCommerce

<= 1.7.7

Broken Access Control vulnerability leading to &yikesthecontenttoggle option update

5.3

1 day ago

Plugin

WP Meta SEO

<= 4.4.8

Social Settings Update vis CrossSite Request Forgery (CSRF) vulnerability

5.4

1 day ago

Plugin

Simple Page Transition

<= 1.4.1

Authenticated Stored CrossSite Scripting (XSS) vulnerability

4.8

1 day ago

Plugin

W-DALIL

<= 2.0

DALIL plugin <= 2.0 Authenticated Stored CrossSite Scripting (XSS) vulnerability

4.8

1 day ago

Plugin

Request a Quote

<= 2.3.7

Authenticated Stored CrossSite Scripting (XSS) vulnerability

4.8

1 day ago

Plugin

Request a Quote

<= 2.3.7

CSV Injection vulnerability

7.4

1 day ago

Plugin

Contact Form 7 Captcha

<= 0.1.1

Reflected CrossSite Scripting (XSS) vulnerability

6.1

2 days ago

Plugin

Advanced Database Cleaner

<= 3.1.0

Reflected CrossSite Scripting (XSS) vulnerability

4.8

2 days ago

Plugin

miniOrange's Google Authenticator

<= 5.5.7

Reflected CrossSite Scripting (XSS) vulnerability

6.1

2 days ago

Plugin

OAuth Single Sign On – SSO (OAuth Client)

<= 6.22.5

Authentication Bypass vulnerability

7.5

2 days ago

Plugin

Jquery Validation For Contact Form 7

<= 5.2

Arbitrary Options Update via CrossSite Request Forgery (CSRF) vulnerability

7.1

2 days ago

Plugin

Discount Rules for WooCommerce

<= 2.4.1

Reflected CrossSite Scripting (XSS) vulnerability

4.8

2 days ago

Plugin

Stripe Payments

<= 2.0.63

Authenticated Stored CrossSite Scripting (XSS) vulnerability

4.8

2 days ago

Plugin

Insights from Google PageSpeed

<= 4.0.6

Multiple CrossSite Request Forgery (CSRF) vulnerabilities

5.4

2 days ago

Plugin

Simple Post Notes

<= 1.7.5

Authenticated Stored CrossSite Scripting (XSS) vulnerability

4.8

2 days ago

Plugin

Page Generator

<= 1.6.5

Arbitrary Keywords Deletion/Duplication via CrossSite Request Forgery (CSRF) vulnerability

5.4

2 days ago

Let us know if we have missed a vulnerability reported elsewhere

Report arrow right Close

Thank you for contributing!

Successfully submit vulnerabilities and receive an invite to our Alliance platform.

Learn more arrow right Close