Known Vulnerabilities for Wordpress Mu by Wordpress
Listed below are 10 of the newest known vulnerabilities associated with "Wordpress Mu" by "Wordpress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104313 json | The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103913 json | The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listi... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103909 json | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103888 json | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103519 json | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103514 json | The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing ... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103426 json | The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versi... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-103421 json | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'R... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103293 json | The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remot... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-102772 json | The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ' |
Not Provided | 2026-10-02 | 2026-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wordpress | Wordpress Mu | 2.9.2 | |||
| Application | Wordpress | Wordpress Mu | 2.9.1.1 | |||
| Application | Wordpress | Wordpress Mu | 2.9.1 | |||
| Application | Wordpress | Wordpress Mu | 2.8.6 | |||
| Application | Wordpress | Wordpress Mu | 2.8.5.2 | |||
| Application | Wordpress | Wordpress Mu | 2.8.5.1 | |||
| Application | Wordpress | Wordpress Mu | 2.8.5 | |||
| Application | Wordpress | Wordpress Mu | 2.8.4 | |||
| Application | Wordpress | Wordpress Mu | 2.8.3 | |||
| Application | Wordpress | Wordpress Mu | 2.8.2 | |||
| Application | Wordpress | Wordpress Mu | 2.8.1 | |||
| Application | Wordpress | Wordpress Mu | 2.7.1 | |||
| Application | Wordpress | Wordpress Mu | 2.7 | |||
| Application | Wordpress | Wordpress Mu | 2.6.5 | |||
| Application | Wordpress | Wordpress Mu | 2.6.3 | |||
| Application | Wordpress | Wordpress Mu | 2.6.2 | |||
| Application | Wordpress | Wordpress Mu | 2.6.1 | |||
| Application | Wordpress | Wordpress Mu | 2.6 | |||
| Application | Wordpress | Wordpress Mu | 1.5.1 | |||
| Application | Wordpress | Wordpress Mu | 1.3.3 |