Security intelligence
Browse the current SiteRespond catalog snapshot of WordPress plugin, theme and core vulnerabilities. The same catalog powers SiteRespond Defence for WordPress — matching installed software on your site and alerting you when a known advisory applies.
Catalog refreshed 24d ago · 42,794 software references (39,455 distinct advisories)
Software references
42,794
39,455 distinct advisories — one advisory may reference multiple components
CISA KEV catalog checked
1,721
Catalog refreshed 4h ago
Current WordPress feed matches
8
Advisories in this feed with a CVE listed in CISA KEV
New in last 30 days
66
Advisories published in the past month
Top vulnerability type
Cross-site scripting
18,607 classified references
Published advisories in the catalog by month.
Classified from advisory titles — useful context, not a guarantee your site is affected.
28,936
classified advisories
13,858 advisories are not classified by vulnerability type.
1–10 of 18,209
Wordpress
wordpress
378 advisories · Latest 12 Aug 2026
Give
give
89 advisories · Latest 28 Aug 2026
Royal Elementor Addons
royal-elementor-addons
86 advisories · Latest 21 Aug 2026
Download Manager
download-manager
83 advisories · Latest 5 Aug 2026
Tutor
tutor
80 advisories · Latest 27 Aug 2026
Ninja Forms
ninja-forms
78 advisories · Latest 23 Jul 2026
Learnpress
learnpress
77 advisories · Latest 24 Aug 2026
Ultimate Member
ultimate-member
75 advisories · Latest 24 Aug 2026
Quiz Master Next
quiz-master-next
74 advisories · Latest 17 Aug 2026
3,153 of 42,794 software references
| Title | Software | Published | CVE | Type |
|---|---|---|---|---|
| Real Estate 7 <= 3.5.2 - Unauthenticated Privilege Escalation | realestate-7 | 17 Apr 2025 | CVE-2025-39459 | Theme |
| Dør <= 2.4 - Unauthenticated Local File Inclusion | dor | 17 Apr 2025 | CVE-2025-39466 | Theme |
| Eduma <= 5.6.4 - Missing Authorization | eduma | 17 Apr 2025 | CVE-2025-39460 | Theme |
| IvyPrep <= 1.6.0 - Unauthenticated Local File Inclusion | ivy-school | 17 Apr 2025 | CVE-2025-39470 | Theme |
| Dessau < 1.9 - Unauthenticated Local File Inclusion | dessau | 17 Apr 2025 | CVE-2025-39463 | Theme |
| Foton <= 2.5.2 - Unauthenticated Local File Inclusion | foton | 17 Apr 2025 | CVE-2025-39458 | Theme |
| Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | betheme | 15 Apr 2025 | CVE-2025-3077 | Theme |
| Tastyc < 2.5.2 - Unauthenticated Local File Inclusion | tastyc | 15 Apr 2025 | CVE-2025-27010 | Theme |
| Grip <= 1.0.9 - Unauthenticated Local File Inclusion | grip | 14 Apr 2025 | CVE-2025-26735 | Theme |
| Eximius <= 2.2 - Authenticated (Subscriber+) Arbitrary File Upload | eximius | 14 Apr 2025 | CVE-2025-26872 | Theme |
Monitoring
Website monitoring for everyone. Connected protection and managed recovery for WordPress. Seeing a vulnerability here does not mean your site is affected — connected monitoring checks your actual installed versions and alerts you when action is needed.
External monitoring from the public internet — no WordPress login required.
£9.99/month/ site
External monitoring only. Watch does not inspect installed WordPress components.
Free public scan first — add monitoring when you are ready.
Connected WordPress monitoring and vulnerability intelligence, with alerts and a direct route into managed recovery.
£29.99/month/ site
Matches your installed core, plugin and theme versions against this catalog.
Requires a WordPress website
We’re onboarding a limited number of sites while monitoring each activation.
Run a free public scan. SiteRespond assesses the incident, issues one fixed quotation, and manages recovery through to verified completion — separate from monitoring plans.