VMP™ Security Logo

VMP™ Security

Intelligence

VMP™ Security Intelligence is a continuously updated WordPress vulnerability database and evolving Threat Intelligence platform that catalogs recorded vulnerabilities in WordPress plugins, themes, and core. The database is actively maintained by our analysts and a community of contributing researchers, with new vulnerabilities added regularly from sources including NVD and GitHub security advisories.

VMP™ Security Intelligence provides access to more than just a public-facing WordPress security resource:

  • A searchable public database of WordPress vulnerabilities with detailed advisory pages for every CVE
  • A free JSON API to query the vulnerability database programmatically for audits, tooling, and integrations
  • Live threat statistics aggregated across the VMP™ Security network
  • A researcher disclosure program — submit vulnerabilities and request CVE IDs directly through our forms

Live network intelligence

Global threat statistics

Aggregated across the VMP™ Security network — past 7 days

39,474
IP addresses tracked
905
Dangerous IPs identified
1,700
Attacks reported (7 days)
17
IPs on the global blocklist

Tracked IPs by threat level

Critical 3,587 High 11,712 Medium 1,748 Low 6,037 Safe 16,390

Global blocklist — highest-threat IPs

threat score ≥ 70
IP address Threat score Attacks Attack types Last seen
216.73.217.117 80 231 firewall_block Jul 12, 2026
192.168.1.241 80 158 ip_blocked, firewall_block Jul 12, 2026
216.73.217.33 70 148 firewall_block Jul 12, 2026
34.82.191.84 70 155 firewall_block Jul 12, 2026
35.196.54.5 70 159 firewall_block Jul 12, 2026
207.148.28.169 70 124 firewall_block Jul 28, 2026
13.38.34.32 70 217 firewall_block Jul 17, 2026
18.188.190.95 70 214 firewall_block Jul 18, 2026
165.245.186.111 70 243 firewall_block Jul 24, 2026
3.16.78.76 70 207 firewall_block Jul 27, 2026

Updated continuously from threat-intelligence data across the VMP™ Security network.

Explore the WordPress vulnerability database

2,012 known vulnerabilities across WordPress core, plugins, and themes — updated daily from NVD and GitHub advisories.

VMP™ Security Intelligence mission statement

Our mission with VMP™ Security Intelligence is to keep accurate, well-documented vulnerability information easily accessible and free for everyone, including enterprises.

Vulnerabilities in open-source WordPress are found by a community of researchers who spend hours testing and reviewing code. Our analysts maintain the database and verify its accuracy, but independent researchers discover the majority of vulnerabilities in the ecosystem. Locking that information behind a paywall only weakens WordPress for everyone, so we keep it open and transparent to help all WordPress users stay secure.

That is why we make our vulnerability information free through all of our delivery methods. It is also why we are committed to building the most useful WordPress vulnerability database we can — without charging for any form of access to the data within it.

Highlights and benefits of VMP™ Security Intelligence

Free API access to the WordPress vulnerability database

Researchers, consultants, and bug-bounty hunters need vulnerability data they can rely on. VMP™ Security Intelligence serves it as a consistent, machine-readable JSON feed. Each advisory carries the CVE ID, CVSS score, CWE, proof-of-concept references where available, and vendor patch details. You can pull it straight into your own tooling — audits, scanners, WP-CLI integrations — without parsing inconsistent formats by hand.

Querying the database programmatically saves hours of manual searching, and access is free.

Read the documentation to start using the vulnerability database API

Live threat intelligence metrics

VMP™ Security Intelligence is more than a vulnerability database. The live statistics on this page show attacks reported across the network over the past 7 days, the IP addresses we're tracking by threat level, and the highest-threat IPs on the global blocklist. Together they give researchers and site owners a current picture of which attack vectors are active against WordPress sites right now.

Flexible search across every vulnerability

One major benefit of the VMP™ Security Intelligence platform is the ability to search our database for vulnerabilities affecting plugins, themes, and core. You can search by name or keyword, and filter by severity, CVE ID, CVSS score, and more — making security research, journalism, and due diligence faster for anyone using the VMP™ Security Intelligence search engine.

Managed by experienced security professionals

The VMP™ Security vulnerability database is managed by a dedicated team with strong backgrounds in web application security. Vulnerabilities in our database are reviewed by our security team before publication, including verification of severity ratings, so you don't have to worry about information quality or accuracy. Our review process is designed to give you reliable, up-to-date information on vulnerabilities in the WordPress ecosystem.

Whether you're a security researcher, an enterprise organization, a hosting provider, or just a simple blog owner, VMP™ Security Intelligence is for you.

If you're looking to easily search our WordPress vulnerability database when conducting an audit or theme vulnerability research, or you're interested in checking out the latest threat statistics, you can explore the VMP™ Security Intelligence public interface right now.

If you've found a vulnerability in a WordPress plugin, theme, or core, you can submit it through our disclosure program today — we review every report and handle the CVE request and vendor notification on your behalf.

If you need programmatic access to the vulnerability data — formatted in JSON for a product, service, or custom integration — the VMP™ Security Intelligence Vulnerability Data API is free to query. The same data that powers our public pages is available to your tools.

If you'd like to protect your own WordPress sites against every vulnerability in this database automatically, VMP™ Security scans and defends your sites with the same intelligence that powers these pages.