wordpress Vulnerabilities and Affected Products
Vulnerabilities associated with WordPress.
Products
Clear product- WordPress28 vulnerabilities
- wordpress-develop17 vulnerabilities
- adserve2 vulnerabilities
- Core2 vulnerabilities
- geo_controller2 vulnerabilities
- max_addons_pro_for_bricks2 vulnerabilities
- royal-elementor-addons2 vulnerabilities
- absolutely_glamorous_custom_admin1 vulnerability
- acf-on-the-go1 vulnerability
- BuddyBoss Theme1 vulnerability
- Buddypress1 vulnerability
- buddypress_cover1 vulnerability
- checkout_mestres1 vulnerability
- contact_form_drag_and_drop_form_builder1 vulnerability
- counter_box1 vulnerability
- cssigniter_elements_team1 vulnerability
- customer_reviews_for_woocommerce1 vulnerability
- directorist1 vulnerability
- easy_social_feed1 vulnerability
- elementsready_addons_for_elementor1 vulnerability
- elespare1 vulnerability
- email_customizer_for_woocommerce1 vulnerability
- enl_newsletter1 vulnerability
- external_database_based_actions1 vulnerability
- File Manager Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-64638HIGH | WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and… | CVSS8.9v4.0 | EPSS0.894% | PoCs23 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-63030CRITICAL | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | CVSS9.8v3.1 | EPSS95.6% | PoCs80 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-60137MEDIUM | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CWE-89Jul 17, 2026 | CVSS5.9v3.1 | EPSS73.1% | PoCs53 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58674MEDIUM | WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 throug… CWE-79Sep 23, 2025 | CVSS5.9v3.1 | EPSS0.201% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58246MEDIUM | WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure VulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2… CWE-201Sep 23, 2025 | CVSS4.3v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior. CWE-669Jul 21, 2025 | CVSS3.7v3.1 | EPSS0.321% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-4439HIGH | WordPress Core <6.5.2 - Cross-Site ScriptingWordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha… | CVSS7.2v3.1 | EPSS70.8% | PoCs5 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-5561MEDIUM | WordPress < 6.3.2 - Unauthenticated Post Author Email DisclosureWordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack | CVSS5.3v3.1 | EPSS3.86% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-2745MEDIUM | WordPress Core < 6.2.1 - Directory TraversalWordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack. | CVSS5.4v3.1 | EPSS79.5% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-3590MEDIUM | WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS RebindingWordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. | CVSS5.9v3.1 | EPSS3.15% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-21662HIGH | Stored XSS in WordPressWordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarou… CWE-79Jan 6, 2022 | CVSS8.0v3.1 | EPSS64.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-21661HIGH | SQL injection in WordPressWordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vul… | CVSS8.0v3.1 | EPSS97.8% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-28034MEDIUM | WordPress wordpress Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')WordPress before 5.5.2 allows XSS associated with global variables. CWE-79Oct 31, 2020 | CVSS6.1v3.1 | EPSS1.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11026HIGH | Specially crafted filenames in WordPress leading to XSSIn affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). | CVSS8.7v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11028MEDIUM | Unauthenticated disclosure of certain private posts in WordPressIn affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). | CVSS5.8v3.1 | EPSS2.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11029MEDIUM | Cross-site scripting in stats method (object cache) in WordPressIn affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). CWE-79Apr 30, 2020 | CVSS5.8v3.1 | EPSS2.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11030MEDIUM | Cross-site scripting (XSS) in Search block in WordPressIn affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). | CVSS6.4v3.1 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11025MEDIUM | Authenticated cross-site scripting (XSS) in WordPress CustomizerIn affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). CWE-79Apr 30, 2020 | CVSS5.8v3.1 | EPSS1.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11027MEDIUM | Password reset links invalidation issue in WordPressIn affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). | CVSS6.1v3.1 | EPSS13.6% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-16781MEDIUM | Stored cross-site scripting (XSS) in WordPress block editorIn WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS. CWE-79Dec 26, 2019 | CVSS5.8v3.1 | EPSS1.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-16780MEDIUM | Stored cross-site scripting (XSS) in WordPress block editorWordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly rec… CWE-79Dec 26, 2019 | CVSS5.8v3.1 | EPSS1.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-8942HIGH | WordPress wordpress Unrestricted Upload of File with Dangerous TypeWordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943. CWE-434Feb 20, 2019 | CVSS8.8v3.0 | EPSS82.7% | PoCs11 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-14028HIGH | WordPress wordpress Unrestricted Upload of File with Dangerous TypeIn WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid p… CWE-434Aug 10, 2018 | CVSS7.2v3.0 | EPSS15.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-14723CRITICAL | WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks. CWE-89Sep 23, 2017 | CVSS9.8v3.0 | EPSS6.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-14726MEDIUM | WordPress wordpress Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor. CWE-79Sep 23, 2017 | CVSS6.1v3.0 | EPSS2.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |