Known vulnerabilities in WordPress
Vendor:
WordPress.ORG
Software:
WordPress
Software CPE:
cpe:2.3:a:wordpress_org:wordpress:*:*:*:*:*:*:*:*
Website:
https://wordpress.org/
Total vulnerabilities:
240
Public exploits:
24
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.1
4.7.35
4.8.30
4.9.31
5.0.27
5.1.24
5.2.26
5.3.23
5.4.21
5.5.20
5.6.19
5.7.17
5.8.15
5.9.16
6.0.14
6.1.12
6.2.11
6.3.10
6.4.10
6.5.10
6.6.7
6.7.7
7.0.4
6.9.7
6.8.8
7.0.3
6.9.6
6.8.7
6.7.6
6.6.6
6.5.9
6.4.9
6.3.9
6.2.10
6.1.11
6.0.13
5.9.15
5.9.14
5.8.14
5.7.16
5.6.18
5.5.19
5.4.20
5.3.22
5.2.25
5.1.23
5.0.26
4.9.30
4.8.29
4.7.34
6.5.1
3.9.38
7.0.2
6.9.5
6.8.6
7.0.1
6.0.12
4.7.33
6.9.4
6.9.3
6.9.2
6.9.1
6.8.5
6.8.4
6.7.5
6.6.5
6.5.8
6.4.8
6.3.8
6.2.9
6.1.10
5.9.13
5.8.13
5.7.15
5.6.17
5.5.18
5.4.19
5.3.21
5.2.24
5.1.22
5.0.25
4.9.29
4.8.28
4.7.32
6.9
5.5.17
5.4.18
5.3.20
5.2.23
5.1.21
5.0.24
4.9.28
4.8.27
4.7.31
6.8.3
6.7.4
6.6.4
6.5.7
6.4.7
6.3.7
6.2.8
6.1.9
6.0.11
5.9.12
5.8.12
5.7.14
5.6.16
6.7.3
6.6.3
6.5.6
6.4.6
6.3.6
6.2.7
6.1.8
6.0.10
5.9.11
5.8.11
5.7.13
5.6.15
5.5.16
5.4.17
5.3.19
5.2.22
5.1.20
5.0.23
4.9.27
4.8.26
4.7.30
4.6.30
6.8.2
4.5.33
4.4.34
4.3.35
4.2.39
4.1.42
6.8.1
6.8
6.7.2
6.7.1
6.7
6.6.2
6.6.1
6.6
6.5.5
6.4.5
6.3.5
6.2.6
6.1.7
6.0.9
5.9.10
5.8.10
5.7.12
5.6.14
5.5.15
5.4.16
5.3.18
5.2.21
5.1.19
5.0.22
4.9.26
4.8.25
4.7.29
4.6.29
4.5.32
4.4.33
4.3.34
4.2.38
4.1.41
6.5.4
6.5.3
6.0.8
6.5.2
6.4.4
6.3.4
6.2.5
6.1.6
6.5
6.4.3
6.3.3
6.2.4
6.1.5
6.0.7
5.9.9
5.8.9
5.7.11
5.6.13
5.5.14
5.4.15
5.3.17
5.2.20
5.1.18
5.0.21
4.9.25
4.8.24
4.7.28
4.6.28
4.5.31
4.4.32
4.3.33
4.2.37
4.1.40
6.4.2
6.4.1
6.4
4.3.32
4.2.36
4.1.39
6.3.2
6.2.3
6.1.4
6.0.6
5.9.8
5.8.8
5.7.10
5.6.12
5.5.13
5.4.14
5.3.16
5.2.19
5.1.17
5.0.20
4.9.24
4.8.23
4.7.27
4.6.27
4.5.30
4.4.31
6.3.1
6.3
5.9.7
6.2.2
6.1.3
6.0.5
4.9.23
4.8.22
4.7.26
4.6.26
4.5.29
4.4.30
4.3.31
4.2.35
4.1.38
6.2.1
6.1.2
6.0.4
5.9.6
5.8.7
5.7.9
5.6.11
5.5.12
5.4.13
5.3.15
5.2.18
5.1.16
5.0.19
6.2
4.0.38
3.9.40
3.8.41
3.7.41
6.1.1
6.1
6.0.3
5.9.5
5.8.6
5.7.8
5.6.10
5.5.11
5.4.12
5.3.14
5.2.17
5.1.15
5.0.18
4.9.22
4.8.21
4.7.25
4.6.25
4.5.28
4.4.29
4.3.30
4.2.34
4.1.37
4.0.37
3.9.39
3.8.40
3.7.40
6.0.2
5.9.4
5.8.5
5.7.7
5.6.9
5.5.10
5.4.11
5.3.13
5.2.16
5.1.14
5.0.17
4.9.21
4.8.20
4.7.24
4.6.24
4.5.27
4.4.28
4.3.29
4.2.33
4.1.36
4.0.36
3.9.37
3.8.39
3.7.39
6.0.1
6.0
5.9.3
5.9.2
5.8.4
5.7.6
5.6.8
5.5.9
5.4.10
5.3.12
5.2.15
5.1.13
5.0.16
4.9.20
4.8.19
4.7.23
4.6.23
4.5.26
4.4.27
4.3.28
4.2.32
4.1.35
4.0.35
3.9.36
3.8.38
3.7.38
5.9.1
5.9
4.0.34
3.9.35
3.8.37
3.7.37
5.8.3
5.7.5
5.6.7
5.5.8
5.4.9
5.3.11
5.2.14
5.1.12
5.0.15
4.9.19
4.8.18
4.7.22
4.6.22
4.5.25
4.4.26
4.3.27
4.2.31
4.1.34
5.4.8
5.3.10
5.2.13
5.8.2
5.7.4
5.6.6
5.5.7
5.1.11
5.0.14
5.8 beta 2
5.8 beta 1
5.3.9
5.8.1
5.7.3
5.6.5
5.5.6
5.4.7
5.2.12
5.8
5.7.2
5.6.4
5.5.5
5.4.6
5.3.8
5.2.11
5.1.10
5.0.13
4.9.18
4.8.17
4.7.21
4.6.21
4.5.24
4.4.25
4.3.26
4.2.30
4.1.33
4.0.33
3.9.34
3.8.36
3.7.36
5.7.1
5.6.3
5.5.4
5.4.5
5.3.7
5.2.10
5.1.9
5.0.12
4.9.17
4.8.16
4.7.20
5.7
5.6.2
5.6.1
5.6
5.5.3
5.4.4
5.3.6
5.2.9
5.1.8
5.5.2
4.7.19
4.6.20
4.5.23
4.4.24
4.3.25
4.2.29
4.1.32
4.0.32
3.9.33
3.8.35
3.7.35
5.4.3
5.3.5
5.2.8
5.1.7
5.0.11
4.9.16
4.8.15
5.5.1
5.5
8.0
7.0
4.4.23
4.3.24
4.2.28
4.1.31
4.0.31
3.9.32
3.8.34
3.7.34
4.5.22
4.6.19
4.7.18
4.8.14
4.9.15
5.0.10
5.1.6
5.2.7
5.3.4
5.4.2
4.4.22
4.4.21
4.3.23
4.3.22
4.2.27
4.2.26
4.1.30
4.1.29
4.0.30
4.0.29
3.9.31
3.9.30
3.8.33
3.8.32
3.7.33
3.7.32
4.5.21
4.6.18
4.7.17
4.8.13
4.9.14
5.0.9
5.1.5
5.2.6
5.3.3
5.4.1
5.4
5.3.2
4.5.20
4.6.17
4.7.16
4.8.12
4.9.13
5.0.8
5.1.4
5.2.5
5.3.1
5.3
4.3.21
4.2.25
4.1.28
4.0.28
3.9.29
3.8.31
3.7.31
4.4.20
4.5.19
4.6.16
4.7.15
4.8.11
4.9.12
5.0.7
5.1.3
5.2.4
4.3.20
4.2.24
4.1.27
4.0.27
3.9.28
3.8.30
3.7.30
4.4.19
4.5.18
4.6.15
4.7.14
4.8.10
4.9.11
5.0.6
5.1.2
5.2.3
5.2
5.2.1
5.2.2
4.8.7
4.8.6
4.8.5
4.7.11
4.7.10
4.7.9
4.6.12
4.6.11
4.6.10
4.5.15
4.5.14
4.5.13
3.8.29
3.8.28
3.8.27
3.8.26
3.8.25
3.7.29
3.7.28
3.7.27
3.7.26
3.7.25
4.4.16
4.4.15
4.4.14
4.3.17
4.3.16
4.3.15
4.2.23
4.2.22
4.2.21
4.2.20
4.2.19
4.1.26
4.1.25
4.1.24
4.1.23
4.1.22
4.0.26
4.0.25
4.0.24
4.0.23
4.0.22
3.9.27
3.9.26
3.9.25
3.9.24
3.9.23
4.7.13
4.6.14
4.5.17
4.4.18
4.3.19
5.1.1
5.0.5
5.0.4
4.9.10
4.8.9
5.1
5.0.3
5.0.2
4.9.9
4.8.8
4.7.12
4.6.13
4.5.16
4.4.17
4.3.18
5.0.1
5.0
4.9.8
4.9.7
4.9.6
4.9.3
4.9.5
4.9.4
4.9.2
3.7.24
3.8.24
3.9.22
4.0.21
4.1.21
4.2.18
4.3.14
4.4.13
4.5.12
4.6.9
4.7.8
4.8.4
4.9.1
4.9
3.7.23
3.8.23
3.9.21
4.0.20
4.1.20
4.2.17
4.3.13
4.4.12
4.5.11
4.6.8
4.7.7
4.8.3
3.7.22
3.8.22
3.9.20
4.0.19
4.1.19
4.2.16
4.3.12
4.4.11
4.5.10
4.6.7
4.7.6
4.8.2
4.8.1
3.7.21
3.8.21
3.9.19
4.0.18
4.1.18
4.2.15
4.3.11
4.4.10
4.5.9
4.6.6
4.8
4.7.5
3.7.20
3.8.20
3.9.18
4.0.17
4.1.17
4.2.14
4.3.10
4.4.9
4.5.8
4.6.5
4.7.4
3.7.19
3.8.19
3.9.17
4.0.16
4.1.16
4.2.13
4.3.9
4.4.8
4.5.7
4.6.4
4.7.3
3.7.18
3.8.18
3.9.16
4.0.15
4.1.15
4.2.12
4.3.8
4.4.7
4.5.6
4.6.3
4.7.2
3.7.17
3.8.17
3.9.15
4.0.14
4.1.14
4.2.11
4.3.7
4.4.6
4.5.5
4.6.2
4.7.1
4.7
3.7.16
3.8.16
3.9.14
4.0.13
4.1.13
4.2.10
4.3.6
4.4.5
4.5.4
4.6.1
4.4.0
4.3.0
3.9.0
1.6.2
3.5.0
3.4.0
1.2.4
1.2.3
2.9.1.1
1.2.5
1.1.1
1.3.3
1.3.2
2.8.5.1
2.8.5.2
1.3
2.0.9rc1
2.1.1beta
0.72
1.4
1.6
0.711
1.3.1
2.1.3 rc2
2.0.10 rc2
2.2 revision5003
2.2.0
2.2 revision5002
2.0.10 rc1
2.1.3 rc1
2.0.3
2.0.2
0.71
0.6.2
0.6.2.1
1.0
1.0.1
1.5
1.2
0.70
0.7
4.6
4.2.9
3.6.1
3.4.2
3.1.1
3.9.12
2.0
2.2.2
4.2.6
3.7
2.3.2
4.4
1.5.1
2.5
4.1
2.8.2
4.0.2
3.0
2.0.8
4.0.4
4.0
2.6
4.5
4.5.1
3.7.13
4.4.3
2.8.6
1.5.1.3
3.7.15
4.1.7
3.3
2.8.1
3.0.1
3.8.6
2.3.1
1.0-platinum
3.1.4
2.6.1
2.1
3.7.14
3.8.10
3.5
1.0.2
1.5-strayhorn
3.1.2
3.7.12
3.7.10
3.7.3
2.6.2
4.4.2
1.5.1.2
2.1.3
2.9.2
4.2
1.5.2
3.7.8
4.2.1
3.0.4
4.0.9
3.8
3.7.1
2.8.3
0.71-gold
2.9.1
3.9.5
4.1.1
3.0.6
3.8.7
3.8.13
2.6.5
4.0.1
4.1.5
3.2
3.1
2.1.1
3.8.9
3.8.2
3.3.3
1.2.1
3.5.2
3.9.7
1.2.2
3.3.1
3.0.5
2.6.3
3.3.2
2.8
2.7.1
4.0.10
3.8.11
4.1.8
4.1.12
2.3
3.8.1
3.9.1
4.0.12
4.0.7
4.3.5
3.4
3.0.3
4.1.3
3.8.15
2.0.11
2.2
3.7.9
4.3.4
4.3.3
4.0.11
2.9
3.9.8
1.5.1.1
4.3.2
4.2.8
2.1.2
2.2.1
3.7.6
2.0.6
4.0.8
3.7.7
4.2.4
4.1.4
2.5.1
3.7.11
3.5.1
3.9.13
1.0.2-blakey
3.1.3
3.7.4
2.0.7
3.4.1
3.9.11
2.3.3
3.8.14
3.8.12
4.2.5
3.7.2
4.0.6
2.0.1
4.1.6
2.7
4.0.5
4.1.10
3.9.6
3.0.2
2.2.3
4.4.1
1.2-delta
3.9.2
3.2.1
3.6
4.1.2
4.2.2
1.0.1-miles
4.0.3
2.0.10
3.9.4
3.8.3
3.9.10
4.4.4
2.0.9
3.9
3.8.5
2.0.5
1.2-mingus
3.7.5
4.1.9
2.8.4
3.9.3
4.1.11
3.8.8
3.8.4
4.3.1
3.9.9
4.3
2.8.5
4.2.3
2.0.4
4.2.7
4.5.3
4.5.2
Vulnerabilities (240)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU141728 - Unrestricted Upload of File with Dangerous Type CVE-2026-65640 |
CWE-434 | Medium | 4.7.35, 4.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4 | 12.08.2026 |
SB20260812207 SB2026081316 SB2026081317 and 3 more |
||
| #VU141177 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141178 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141179 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141180 - Improper Access Control |
CWE-284 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141181 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | Medium | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141182 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | Medium | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141183 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | Medium | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141184 - Improper input validation |
CWE-20 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141185 - Authentication Bypass Using an Alternate Path or Channel |
CWE-288 | Medium | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141186 - Server-Side Request Forgery (SSRF) |
CWE-918 | Medium | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141176 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 |
||
| #VU141175 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-64638 |
CWE-79 | High | 4.7.34, 4.8.29, 4.9.30, 5.0.26, 5.1.23, 5.2.25, 5.3.22, 5.4.20, 5.5.19, 5.6.18, 5.7.16, 5.8.14, 5.9.14, 6.0.13, 6.1.11, 6.2.10, 6.3.9, 6.4.9, 6.5.9, 6.6.6, 6.7.6, 6.8.7, 6.9.6, 7.0.3 | 07.08.2026 |
SB2026080702 SB2026080714 SB2026080715 and 9 more |
||
| #VU139077 - Interpretation Conflict CVE-2026-63030 |
CWE-436 | Critical | 6.9.5, 7.0.2 | 22.07.2026 |
SB2026072222 |
||
| #VU139076 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-60137 |
CWE-89 | Critical | 6.8.6, 6.9.5, 7.0.2 | 22.07.2026 |
SB2026072222 SB2026072443 |
||
| #VU116652 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-58674 |
CWE-79 | Low | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | 07.10.2025 |
SB2025100716 SB2025122343 |
||
| #VU116650 - Improper Access Control CVE-2025-58246 |
CWE-284 | Medium | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | 07.10.2025 |
SB2025100716 SB2025122343 |
||
| #VU93316 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-6306 |
CWE-22 | Medium | 4.1.41, 4.2.38, 4.3.34, 4.4.33, 4.5.32, 4.6.29, 4.7.29, 4.8.25, 4.9.26, 5.0.22, 5.1.19, 5.2.21, 5.3.18, 5.4.16, 5.5.15, 5.6.14, 5.7.12, 5.8.10, 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5 | 25.06.2024 |
SB20240625118 SB2024070335 SB2024070336 and 1 more |
||
| #VU93315 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-32111 |
CWE-79 | Low | 4.1.41, 4.2.38, 4.3.34, 4.4.33, 4.5.32, 4.6.29, 4.7.29, 4.8.25, 4.9.26, 5.0.22, 5.1.19, 5.2.21, 5.3.18, 5.4.16, 5.5.15, 5.6.14, 5.7.12, 5.8.10, 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5 | 25.06.2024 |
SB20240625118 SB2024070335 SB2024070336 and 1 more |
||
| #VU93314 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-6307 |
CWE-79 | Medium | 4.1.41, 4.2.38, 4.3.34, 4.4.33, 4.5.32, 4.6.29, 4.7.29, 4.8.25, 4.9.26, 5.0.22, 5.1.19, 5.2.21, 5.3.18, 5.4.16, 5.5.15, 5.6.14, 5.7.12, 5.8.10, 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5 | 25.06.2024 |
SB20240625118 SB2024070335 SB2024070336 and 1 more |
Showing elements 1 - 20 out of 240