When a new vulnerability is disclosed, attackers often start exploiting it within hours — frequently before a patch is even widely installed. So "what should I fix first?" should be driven by what is actually being attacked, not just a severity label.
PowerSEC cross-references every vulnerability we detect on your sites against the CISA Known Exploited Vulnerabilities (KEV) catalog — the U.S. government's list of CVEs confirmed to be exploited in the wild.
What you'll see
- On Dashboard → Vulnerabilities, any vulnerability whose CVE is in the KEV catalog gets a 🔥 Actively exploited badge.
- These are sorted to the top of the list — above non-exploited "critical" items — because an actively exploited High is often a bigger real-world risk than a Critical nobody is attacking yet.
- A banner summarises how many of your vulnerabilities are actively exploited right now.
What to do
- Update or remove the affected plugin or theme first. This removes the known vulnerability.
- If you can't update immediately, PowerSEC Pro may have a virtual-patch rule for some actively exploited issues that blocks the attack pattern while you schedule the update. Not every vulnerability has one.
- Check again after updating to confirm the vulnerability is cleared.
Good to know
- The KEV list is refreshed automatically and fails safe: if it is temporarily unreachable, no vulnerability is ever hidden or down-ranked — you simply won't see the badge until it refreshes.
- A vulnerability not flagged isn't necessarily safe to ignore — it just isn't on the confirmed-exploited list. Severity still matters.