Known Vulnerabilities for products from WordPress
Listed below are 20 of the newest known vulnerabilities associated with the vendor "WordPress".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101925 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-101147 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-100184 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-100179 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-100143 json | Not Provided | 2026-09-30 | 2026-09-30 | |
| CVE-2026-97661 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-97347 json | Not Provided | 2026-09-30 | 2026-09-30 | |
| CVE-2026-97319 json | Not Provided | 2026-09-27 | 2026-09-28 | |
| CVE-2026-97316 json | Not Provided | 2026-09-30 | 2026-09-30 | |
| CVE-2026-97227 json | Not Provided | 2026-09-27 | 2026-09-28 | |
| CVE-2026-87902 json | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` fi... | Not Provided | 2026-09-22 | 2026-09-28 |
| CVE-2026-63030 json | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, com... | Not Provided | 2026-07-17 | 2026-07-22 |
| CVE-2026-60137 json | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parame... | Not Provided | 2026-07-17 | 2026-07-29 |
| CVE-2024-8914 json | The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress... | Not Provided | 2024-09-25 | 2026-04-08 |
| CVE-2023-39999 json | Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from... | 4.3 - MEDIUM | 2023-10-13 | 2023-11-20 |
| CVE-2023-38000 json | Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6... | 5.4 - MEDIUM | 2023-10-13 | 2023-10-16 |
| CVE-2023-22622 json | WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security upda... | 5.3 - MEDIUM | 2023-01-05 | 2023-11-07 |
| CVE-2023-5561 json | WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to... | 5.3 - MEDIUM | 2023-10-16 | 2023-11-20 |
| CVE-2023-2745 json | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. T... | Not Provided | 2023-05-17 | 2026-04-08 |
| CVE-2022-47174 json | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions. | 8.8 - HIGH | 2023-05-25 | 2023-06-01 |
Known software with vulnerabilities from WordPress
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wordpress | Plugin Newsletter Plugin | 1.5 |
| Application | Wordpress | Slideshow Gallery2 | - |
| Application | Wordpress | Wordpress | - |
| Application | Wordpress | Wordpress Mu | 1.1 |