Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WordPress — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting WordPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WordPress operates as an open-source content management system powering a significant portion of the global web, primarily enabling users to create and manage websites without extensive coding knowledge. Its widespread adoption has made it a frequent target for attackers, resulting in thirty-two recorded Common Vulnerabilities and Exposures. Historically, the platform has been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insecure plugin architectures or insufficient input validation. Security incidents frequently involve unauthorized administrative access or data exfiltration through exploited themes and extensions. While the core software undergoes rigorous review, the extensive ecosystem of third-party contributions introduces variability in security hygiene. Regular updates and strict adherence to security best practices are essential for mitigating risks associated with its complex, modular structure and high visibility in the digital landscape.

Found 15 results / 36Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution — WordPress 9.8 Critical2026-07-17
CVE-2026-60137 WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query — WordPress 5.9 Medium2026-07-17
CVE-2025-58674 WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability — WordPressCWE-79 5.9 Medium2025-09-23
CVE-2025-58246 WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability — WordPressCWE-201 4.3 Medium2025-09-23
CVE-2025-54352 WordPress 安全漏洞 — WordPressCWE-669 3.7 Low2025-07-21
CVE-2023-5561 WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure — WordPress 5.3 -2023-10-16
CVE-2022-3590 WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding — WordPress 5.9 -2022-12-14
CVE-2020-11026 Specially crafted filenames in WordPress leading to XSS — WordPressCWE-707 8.7 High2020-04-30
CVE-2020-11028 Unauthenticated disclosure of certain private posts in WordPress — WordPressCWE-284 5.8 Medium2020-04-30
CVE-2020-11029 Cross-site scripting in stats method (object cache) in WordPress — WordPressCWE-79 5.8 Medium2020-04-30
CVE-2020-11030 Cross-site scripting (XSS) in Search block in WordPress — WordPressCWE-707 6.4 Medium2020-04-30
CVE-2020-11025 Authenticated cross-site scripting (XSS) in WordPress Customizer — WordPressCWE-79 5.8 Medium2020-04-30
CVE-2020-11027 Password reset links invalidation issue in WordPress — WordPressCWE-672 6.1 Medium2020-04-30
CVE-2019-16781 Stored cross-site scripting (XSS) in WordPress block editor — WordPressCWE-79 5.8 Medium2019-12-26
CVE-2019-16780 Stored cross-site scripting (XSS) in WordPress block editor — WordPressCWE-79 5.8 Medium2019-12-26

This page lists every published CVE security advisory associated with WordPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.