Known vulnerabilities in WordPress

Software: WordPress
Software CPE: cpe:2.3:a:wordpress_org:wordpress:*:*:*:*:*:*:*:*
Total vulnerabilities: 251
Public exploits: 24
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WordPress WordPress is affected by 251 known vulnerabilities: 3 critical, 22 high, 87 medium, 139 low Critical High Medium Low

Vulnerabilities (251)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU151804 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2026-87902
CWE-98 Critical
No
No
4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, 7.1.2 23.09.2026 SB2026092336
SB2026092350
SB2026092351
and 5 more
#VU151466 - Missing Authorization
CWE-862 Medium
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151465 - Cross-Site Request Forgery (CSRF)
CWE-352 Medium
No
No
4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151464 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151463 - Missing Authorization
CWE-862 Low
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151462 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151461 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Medium
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151460 - Missing Authorization
CWE-862 Low
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151459 - Missing Authorization
CWE-862 Medium
No
No
5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151458 - Missing Authorization
CWE-862 Low
No
No
4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU151457 - Incorrect Authorization
CWE-863 Low
No
No
5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1 20.09.2026 SB2026092008
#VU141728 - Unrestricted Upload of File with Dangerous Type
CVE-2026-65640
CWE-434 Medium
No
No
4.7.35, 4.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4 12.08.2026 SB20260812207
SB2026081316
SB2026081317
and 3 more
#VU141177 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141178 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141179 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141180 - Improper Access Control
CWE-284 Low
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141181 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141182 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141183 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702
#VU141176 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
6.8.7, 6.9.6, 7.0.3 07.08.2026 SB2026080702


Showing elements 1 - 20 out of 251