wordpress
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting wordpress.
- CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...8.1
- CVE-2026-65640WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the serv...8.8
- CVE-2026-64638WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be ...
- CVE-2026-45293WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability8.6
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionKEV9.8
- CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryKEV5.9
- CVE-2020-37233WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting6.4
- CVE-2023-54333Social-Share-Buttons 2.2.3 - SQL Injection via project_id Parameter8.2
- CVE-2025-58674WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability5.9
- CVE-2025-58246WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability4.3
- CVE-2025-54352WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.3.7
- CVE-2022-4973WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function4.9
- CVE-2024-8914Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2024-4439WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This ...7.2
- CVE-2024-31211Remote Code Execution in `WP_HTML_Token`5.5