CVE Tools

Wordpress-foundation

178 CVEs tracked since 2019. Since Sep 2019, none of them reached CISA KEV.

Wordpress-foundation CVEs per month

Sep 2019 to Feb 2025. Point at a month, or focus the strip and use the arrow keys.
Wordpress-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-0970
2019-1060
2019-11null or fewer
2019-1250
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0640
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-1090
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-0940
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-0290
2022-0340
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01140
2023-0260
2023-03null or fewer
2023-0440
2023-0570
2023-0640
2023-0760
2023-0860
2023-09null or fewer
2023-1060
2023-11null or fewer
2023-1250
2024-0170
2024-02null or fewer
2024-0390
2024-04120
2024-0580
2024-0650
2024-07null or fewer
2024-0870
2024-09null or fewer
2024-1080
2024-1150
2024-12null or fewer
2025-0160
2025-0250

Products

The products that kept showing up in Wordpress-foundation's monthly top three, with their CVEs summed over those months.

  1. WordPress408 months
  2. Tutor Lms52 months
  3. Forminator42 months
  4. Jeg Elementor Kit43 months
  5. BLOG2SOCIAL22 months
  6. Eventon Lite21 month
  7. Givewp22 months
  8. Post Meta Data Manager21 month
  9. Post Smtp Mailer21 month
  10. Ultimate Membership Pro21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wordpress-foundation.

  1. CVE-2026-3906WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API4.3
  2. CVE-2025-9501W3 Total Cache < 2.8.13 - Unauthenticated Command Injection9.0
  3. CVE-2025-11833Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure9.8
  4. CVE-2025-10294OwnID Passwordless Login <= 1.3.4 - Authentication Bypass9.8
  5. CVE-2025-58674WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability5.9
  6. CVE-2025-58246WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability4.3
  7. CVE-2025-9807The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection7.5
  8. CVE-2025-24000WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability8.8
  9. CVE-2025-5947Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie9.8
  10. CVE-2025-7697Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function9.8
  11. CVE-2025-6043Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal <= 17.0 - Authenticated (Subscriber+) Arbitrary File Deletion8.1
  12. CVE-2025-6463Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion8.8
  13. CVE-2025-5746Drag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload9.8
  14. CVE-2025-5314Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source'6.1
  15. CVE-2025-53339WordPress Devnex Addons For Elementor plugin <= 1.0.9 - Local File Inclusion Vulnerability7.5

The record

Peak rank
#51 in Oct 2020
Busiest month shown
Jan 2023, 14 CVEs
Months with a KEV entry
0 since Sep 2019
Monthly snapshots
27 since 2019
Wordpress-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store