Wordfence is a global team of WordPress security analysts, threat researchers, software engineers, and support staff. We are the leaders in our field, and we focus exclusively on securing WordPress websites, and on WordPress security research. We provide 24-hour service, 365 days a year for mission-critical websites, with a 1 hour response time via Wordfence Response. To learn more about our products, check out our Product Comparison Page.
Wordfence leads the industry in login security controls, including brute force protection, XMLRPC protection, reCAPTCHA to block automated attacks, and IP access control.
Centralized security events and template-based security configuration management, 100% free. Our customers constantly tell us that Wordfence Central is too good to be true. Even users of the free version of Wordfence get full access to Wordfence Central at no cost.
Wordfence Care and Response customers receive hands-on support to install, configure, and optimize Wordfence along with continuous security monitoring from our team. Wordfence Response customers get 24/7 support and monitoring with a 1-hour response time.
Two-factor authentication or 2FA has become a standard requirement for any secure service. Wordfence provides robust 2FA for your admins and users using secure open standards.
Wordfence maintains the largest WordPress-specific malware database in the world. Using this intelligence trove, we produce malware signatures to block intrusion attempts, detect malicious activity, and provide robust security for your WordPress site.
The Wordfence Threat Intelligence Team continuously discovers new vulnerabilities in WordPress core, plugins, and themes. We immediately release new firewall rules that protect against these vulnerabilities, which are deployed in real-time to our paid customers providing the best available intrusion prevention for WordPress.
Our unique data is what makes Wordfence so effective. Premium, Care, and Response customers receive real-time updates to protection and detection rules.
Last week, there were 82 vulnerabilities disclosed in 59 WordPress Plugins and 11 WordPress themes, along with 6 in WordPress Core, that have been added to the Wordfence Intelligence Vulnerability Database, and there were 26 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site …
Read More
The Wordfence Threat Intelligence team has been monitoring an increase in attacks targeting a Cross-Site Scripting vulnerability in Beautiful Cookie Consent Banner, a WordPress plugin installed on over 40,000 sites. The vulnerability, which was fully patched in January in version 2.10.2, offers unauthenticated attackers the ability to add malicious JavaScript to a website, potentially allowing …
Read More
On April 25, 2023, our Wordfence Threat Intelligence team identified and began the responsible disclosure process for a stored Cross-Site Scripting (XSS) vulnerability in W3 Eden’s Download Manager plugin, which is actively installed on more than 100,000 WordPress websites, making it one of the most popular download management plugins. The vulnerability enables threat actors with …
Read More
Last week, there were 139 vulnerabilities disclosed in 105 WordPress Plugins and 2 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 47 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with …
Read More
On May 11 2023, Essential Addons for Elementor, a WordPress plugin with over one million active installations, released a patch for a critical vulnerability that made it possible for any unauthenticated user to reset arbitrary user passwords, including user accounts with administrative-level access. This vulnerability was discovered and responsibly disclosed by security researcher Rafie Muhammed. …
Read More
On May 16, 2023, the WordPress core team released WordPress 6.2.1, which contains patches for 5 vulnerabilities, including a Medium Severity Directory Traversal vulnerability, a Medium-Severity Cross-Site Scripting vulnerability, and several lower-severity vulnerabilities. These patches have been backported to every version of WordPress since 4.1. WordPress has supported automatic core updates for security releases since …
Read More
Receive WordPress security news before publication.