Product guide
Vulnerability intelligence
Use Witen's independent advisory catalog to understand publisher-confirmed WordPress issues and whether validated exploit behavior is appearing across protected environments.
Read the advisory model
An advisory is a sourced security publication, not merely a CVE row. WordPress.org may confirm several issues in one release while assigning a public identifier to only some of them. Witen preserves the publisher, canonical source URL, retrieval time, evidence class, and confidence instead of inventing missing identifiers.
- Publisher confirmed means the component publisher publicly confirmed the claim.
- Coordinated disclosure means Witen validated the issue with the affected vendor before publication.
- Independent reproduction means Witen reproduced the issue in an authorized isolated environment.
- Third-party reports and observed suspicious behavior do not become confirmed vulnerabilities by themselves.
Treat version evidence conservatively
Affected and fixed versions are separate claims. A security release proves that its release contains a fix; it does not automatically prove that every earlier version is affected.
Understand lifecycle changes
Published and superseded
Published records are customer-visible. Superseded records remain visible and point operators toward newer evidence instead of disappearing.
Disputed and withdrawn
Disputed records retain the dispute so decisions remain auditable. Withdrawn records are removed from the customer feed and retain an internal reason and history. Embargoed and draft records never enter customer APIs.
Interpret observed exploitation
Witen only associates traffic with an advisory through a validated detection signature. A matching path shape or generic WordPress probe is not enough. Network observations become customer-visible only after at least three independent sensors contribute matches.
- Displayed values are aggregate event, sensor, and source-address counts.
- Customer IDs, hostnames, raw requests, user agents, source addresses, cookies, and credentials are not published.
- No visible match means Witen has no qualifying evidence; it does not prove exploitation is absent.
- CDN and shared-client context remains part of classifier validation to avoid treating shared infrastructure as a malicious identity.
Respond to an advisory
- Confirm the component and installed version on every protected asset.
- Follow the publisher's fixed-version guidance when it is available.
- Back up and stage the update according to the component vendor's procedure.
- Use Witen Activity and local Warden evidence to investigate matching behavior; do not use aggregate network counts as attribution.
- Document the update and verify the component version after deployment.
Report a vulnerability
Email security@witenlabs.com with the affected component and versions, reproducible steps, impact, and your preferred disclosure terms. Do not send credentials, production personal data, or exploit traffic against systems you do not own or have permission to test.