Curated resource guide
WordPress Vulnerability Intelligence
Turn WordPress vulnerability disclosures into informed production decisions. These resources help interpret CVEs, severity, exploit conditions, affected versions, patch availability, active exploitation, disclosure timelines, install-base context, and trusted advisory feeds so teams can prioritize action instead of reacting to headlines.
Scope
What this guide covers
- WordPress core, plugin and theme vulnerability advisories
- CVEs
- CVSS and severity interpretation
- affected and patched versions
- exploit prerequisites
- authentication requirements
- privilege requirements
- active exploitation
- proof-of-concept context
- vendor advisories
- Wordfence/Patchstack/WPScan and other trusted feeds
- disclosure timelines
- patch availability
- virtual patching
- plugin install-base context
- risk prioritization
- false positives
- monitoring new disclosures
- and turning raw vulnerability data into production actions
Selected references
Curated resources
Links open the original publisher so you can use the complete, current material in context.
- 01Recommended starting point
WPScan WordPress Vulnerability Database
Search WordPress core advisories with affected versions, fixes, references, CVEs, and severity context.
wpscan.com - 02
Wordfence Intelligence Vulnerability Database
A WordPress-specific database that combines disclosure details, affected plugins, severity, and remediation information.
wordfence.com - 03
Patchstack Vulnerability Database
Track plugin, theme, and core disclosures with affected versions, fixes, and virtual-patching context.
patchstack.com - 04
National Vulnerability Database
Use the official US vulnerability repository to cross-check CVEs, references, scoring, and affected software data.
nvd.nist.gov - 05
CISA Known Exploited Vulnerabilities Catalog
Prioritize vulnerabilities backed by evidence of real-world exploitation rather than severity scores alone.
cisa.gov - 06
FIRST CVSS
Read the scoring specification and calculator guidance before turning a CVSS number into an operational decision.
first.org - 07
WordPress Security Releases
Follow official WordPress security and maintenance releases together with the versions that contain each fix.
wordpress.org