wordpress Vulnerabilities and Affected Products
Vulnerabilities associated with Core.
Products
Clear product- WordPress28 vulnerabilities
- wordpress-develop17 vulnerabilities
- adserve2 vulnerabilities
- Core2 vulnerabilities
- geo_controller2 vulnerabilities
- max_addons_pro_for_bricks2 vulnerabilities
- royal-elementor-addons2 vulnerabilities
- absolutely_glamorous_custom_admin1 vulnerability
- acf-on-the-go1 vulnerability
- BuddyBoss Theme1 vulnerability
- Buddypress1 vulnerability
- buddypress_cover1 vulnerability
- checkout_mestres1 vulnerability
- contact_form_drag_and_drop_form_builder1 vulnerability
- counter_box1 vulnerability
- cssigniter_elements_team1 vulnerability
- customer_reviews_for_woocommerce1 vulnerability
- directorist1 vulnerability
- easy_social_feed1 vulnerability
- elementsready_addons_for_elementor1 vulnerability
- elespare1 vulnerability
- email_customizer_for_woocommerce1 vulnerability
- enl_newsletter1 vulnerability
- external_database_based_actions1 vulnerability
- File Manager Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-63030CRITICAL | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | CVSS9.8v3.1 | EPSS95.6% | PoCs80 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-60137MEDIUM | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CWE-89Jul 17, 2026 | CVSS5.9v3.1 | EPSS73.1% | PoCs53 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |