WordPress Security

News & Research

Published by Wordfence — the security team protecting WordPress sites since 2012, now 5+ million strong.


Includes weekly, monthly and quarterly vulnerability reports, articles on the latest threats and vulnerabilities in the WordPress space.

Search the blog

Search by vulnerability, plugin name, attack type, or CVE.

Tip: try “SQLi”, “XSS”, “file upload”, or a plugin name.

Join the WordPress Security Mailing List

Join our extremely popular WordPress Security Mailing List to get security alerts, news, and research in your inbox before it appears anywhere else.”

 

Get WordPress security news, threat intelligence breakdowns, and expert insights delivered in video format. Subscribe to the official Wordfence YouTube channel for coverage of the latest high-impact plugin and theme vulnerabilities, malware trends, and security best practices.

Latest Episode

Wordfence Security News

WordPress Security Essentials Series

WordPress Security in 60 Seconds


Guides, research, and tools to strengthen your WordPress security.

wordfence free logo
Wordfence Premium Logo
Wordfence Care Logo
Wordfence Response Logo
Wordfence CLI Logo

Secure your Site with Wordfence

Choose the protection that fits your needs.

  • Wordfence Free: Essential protection for personal and low-risk sites.
  • Wordfence Premium: Real-time protection for business and eCommerce sites.
  • Wordfence Care: Expert cleanup and hands-on security management.
  • Wordfence Response: like Wordfence Care but with 1-hour incident response.
  • Wordfence CLI: Fast, scalable command-line malware and vulnerability scanner for WordPress environments.

How to Clean a Hacked Site

Step-by-step guidance on identifying, scanning, and cleaning a hacked WordPress site using the Wordfence security tools. If you prefer expert help, choose Wordfence Care or Response for hands-on remediation and recovery assistance.

2024 Annual WordPress Security Report

2024 Annual WordPress Security Report

A comprehensive breakdown of 2024 vulnerabilities and real-world attack trends, with practical context for site owners and the broader WordPress community.

Wordfence Threat Intelligence

Browse Wordfence’s industry-leading WordPress vulnerability database with 12,000+ records across plugins, themes, and core—actively maintained with new entries added weekly.

Bug Bounty Program and Vulnerability Portal

Help make the internet safer and get rewarded for responsible disclosure with Wordfence’s Bug Bounty Program.

Are you a WordPress vendor? Register for our Vulnerability Portal and work with us to protect the WordPress community.