WordPress
382 CVEs tracked. 5 of them are in CISA KEV.
This hub aggregates every CVE we track for WordPress, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
WordPress CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 2 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 2 |
| 2026-09 | 2 |
Severity
How the 382 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical30
- High82
- Medium250
- Low19
Latest CVEs
The 15 most recently published vulnerabilities affecting WordPress.
- CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...8.1
- CVE-2026-93485WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-65640WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the serv...8.8
- CVE-2026-64638WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be ...—
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution9.8
- CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query5.9
- CVE-2026-3906WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API4.3
- CVE-2025-58674WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability5.9
- CVE-2025-58246WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability4.3
- CVE-2025-54352WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.3.7
- CVE-2025-31408WordPress Zoho Flow plugin <= 2.13.3 - Broken Access Control vulnerability4.3
- CVE-2022-4973WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function4.9
- CVE-2024-32111WordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability5.0
- CVE-2024-31111WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2024-6307WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API6.4
Product grouping is registry-driven, with AI assist and human review. How it works