Threat intelligence
Catalog health
WordPress advisory feed last successfully refreshed 4d ago · CISA KEV catalog refreshed 1h ago.
SiteRespond imports WordPress plugin, theme and core advisories from Wordfence Intelligence into a private catalog used for Defence version matching. CVE identifiers are cross-referenced with the CISA Known Exploited Vulnerabilities catalog. Each public record stores source provenance and links to the authoritative original.
Public pages summarise imported fields with attribution. Attribution alone does not necessarily grant redistribution rights — review the respective source terms before republishing advisory content elsewhere.
The WordPress advisory feed and CISA KEV catalog are promoted on an automated daily schedule. The timestamp shown on the intelligence catalog reflects the last successful WordPress feed promotion, not live per-request API calls.
Vulnerability types displayed in charts and software profiles are inferred from advisory titles using pattern rules (for example, matching “SQL injection”, “XSS”, or “remote code execution”). This is useful context — not a formal CWE taxonomy. Advisories that do not match a rule appear as unclassified in summary statistics.
Whether an issue requires authentication is also inferred from advisory titles — looking for phrases such as “unauthenticated” or role names like “subscriber” or “administrator”. When the feed title does not specify authentication, we label it unspecified and recommend reading the source advisory.
After import, SiteRespond compares each advisory CVE against the full CISA KEV catalog. “CISA KEV catalog checked” is the size of that authoritative list. “Current WordPress feed matches” is how many advisories in this WordPress feed carry a CVE also listed in KEV — not the number of exploited WordPress vulnerabilities SiteRespond independently confirms.
When the upstream feed marks an advisory as withdrawn, SiteRespond excludes it from the active public catalog on the next successful promotion. Historical URLs may return not found after withdrawal.
Seeing a vulnerability listed does not mean your site is affected. Exposure depends on whether you run the affected software at a vulnerable version.
We do not claim: