VMP™ Security
Intelligence
VMP™ Security Intelligence is a continuously updated WordPress vulnerability database and evolving Threat Intelligence platform that catalogs recorded vulnerabilities in WordPress plugins, themes, and core. The database is actively maintained by our analysts and a community of contributing researchers, with new vulnerabilities added regularly from sources including NVD and GitHub security advisories.
VMP™ Security Intelligence provides access to more than just a public-facing WordPress security resource:
- A searchable public database of WordPress vulnerabilities with detailed advisory pages for every CVE
- A free JSON API to query the vulnerability database programmatically for audits, tooling, and integrations
- Live threat statistics aggregated across the VMP™ Security network
- A researcher disclosure program — submit vulnerabilities and request CVE IDs directly through our forms
Live network intelligence
Global threat statistics
Aggregated across the VMP™ Security network — past 7 days
Tracked IPs by threat level
Global blocklist — highest-threat IPs
threat score ≥ 70| IP address | Threat score | Attacks | Attack types | Last seen |
|---|---|---|---|---|
| 216.73.217.117 | 80 | 231 | firewall_block | Jul 12, 2026 |
| 192.168.1.241 | 80 | 158 | ip_blocked, firewall_block | Jul 12, 2026 |
| 216.73.217.33 | 70 | 148 | firewall_block | Jul 12, 2026 |
| 34.82.191.84 | 70 | 155 | firewall_block | Jul 12, 2026 |
| 35.196.54.5 | 70 | 159 | firewall_block | Jul 12, 2026 |
| 207.148.28.169 | 70 | 124 | firewall_block | Jul 28, 2026 |
| 13.38.34.32 | 70 | 217 | firewall_block | Jul 17, 2026 |
| 18.188.190.95 | 70 | 214 | firewall_block | Jul 18, 2026 |
| 165.245.186.111 | 70 | 243 | firewall_block | Jul 24, 2026 |
| 3.16.78.76 | 70 | 207 | firewall_block | Jul 27, 2026 |
Updated continuously from threat-intelligence data across the VMP™ Security network.
Explore the WordPress vulnerability database
2,012 known vulnerabilities across WordPress core, plugins, and themes — updated daily from NVD and GitHub advisories.
VMP™ Security Intelligence mission statement
Our mission with VMP™ Security Intelligence is to keep accurate, well-documented vulnerability information easily accessible and free for everyone, including enterprises.
Vulnerabilities in open-source WordPress are found by a community of researchers who spend hours testing and reviewing code. Our analysts maintain the database and verify its accuracy, but independent researchers discover the majority of vulnerabilities in the ecosystem. Locking that information behind a paywall only weakens WordPress for everyone, so we keep it open and transparent to help all WordPress users stay secure.
That is why we make our vulnerability information free through all of our delivery methods. It is also why we are committed to building the most useful WordPress vulnerability database we can — without charging for any form of access to the data within it.
Highlights and benefits of VMP™ Security Intelligence
Free API access to the WordPress vulnerability database
Researchers, consultants, and bug-bounty hunters need vulnerability data they can rely on. VMP™ Security Intelligence serves it as a consistent, machine-readable JSON feed. Each advisory carries the CVE ID, CVSS score, CWE, proof-of-concept references where available, and vendor patch details. You can pull it straight into your own tooling — audits, scanners, WP-CLI integrations — without parsing inconsistent formats by hand.
Querying the database programmatically saves hours of manual searching, and access is free.
Read the documentation to start using the vulnerability database API
Live threat intelligence metrics
VMP™ Security Intelligence is more than a vulnerability database. The live statistics on this page show attacks reported across the network over the past 7 days, the IP addresses we're tracking by threat level, and the highest-threat IPs on the global blocklist. Together they give researchers and site owners a current picture of which attack vectors are active against WordPress sites right now.
Flexible search across every vulnerability
One major benefit of the VMP™ Security Intelligence platform is the ability to search our database for vulnerabilities affecting plugins, themes, and core. You can search by name or keyword, and filter by severity, CVE ID, CVSS score, and more — making security research, journalism, and due diligence faster for anyone using the VMP™ Security Intelligence search engine.
Managed by experienced security professionals
The VMP™ Security vulnerability database is managed by a dedicated team with strong backgrounds in web application security. Vulnerabilities in our database are reviewed by our security team before publication, including verification of severity ratings, so you don't have to worry about information quality or accuracy. Our review process is designed to give you reliable, up-to-date information on vulnerabilities in the WordPress ecosystem.
Whether you're a security researcher, an enterprise organization, a hosting provider, or just a simple blog owner, VMP™ Security Intelligence is for you.
If you're looking to easily search our WordPress vulnerability database when conducting an audit or theme vulnerability research, or you're interested in checking out the latest threat statistics, you can explore the VMP™ Security Intelligence public interface right now.
If you've found a vulnerability in a WordPress plugin, theme, or core, you can submit it through our disclosure program today — we review every report and handle the CVE request and vendor notification on your behalf.
If you need programmatic access to the vulnerability data — formatted in JSON for a product, service, or custom integration — the VMP™ Security Intelligence Vulnerability Data API is free to query. The same data that powers our public pages is available to your tools.
If you'd like to protect your own WordPress sites against every vulnerability in this database automatically, VMP™ Security scans and defends your sites with the same intelligence that powers these pages.