Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WordPress — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting WordPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WordPress operates as an open-source content management system powering a significant portion of the global web, primarily enabling users to create and manage websites without extensive coding knowledge. Its widespread adoption has made it a frequent target for attackers, resulting in thirty-two recorded Common Vulnerabilities and Exposures. Historically, the platform has been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insecure plugin architectures or insufficient input validation. Security incidents frequently involve unauthorized administrative access or data exfiltration through exploited themes and extensions. While the core software undergoes rigorous review, the extensive ecosystem of third-party contributions introduces variability in security hygiene. Regular updates and strict adherence to security best practices are essential for mitigating risks associated with its complex, modular structure and high visibility in the digital landscape.

HighCVE-2026-170442026-08-09
WordPress File Upload < 5.1.8 – Unauthenticated SQL Injection via uniqueuploadid | CVE 2026-17044 | Plugin Vulnerabiliti
MediumCVE-2026-166082026-08-08
Download Monitor < 5.2.6 – Unauthenticated Download Log Injection | CVE 2026-16608 | Plugin Vulnerabilities
Medium2026-08-08
Code Embed <= 2.6 - Contributor Stored Cross-Site Scripting via Remote URL Embed · Advisory · dartiss/code-embed · GitHu
HighCVE-2026-159912026-08-07
File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd'
MediumCVE-2026-152812026-08-07
User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
HighCVE-2026-646382026-08-06
WordPress 7.0.3 release – WordPress News
MediumCVE-2026-119772026-08-06
WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
HighCVE-2026-74442026-08-05
Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery
MediumCVE-2026-87902026-08-05
Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting
HighCVE-2026-61472026-08-05
LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
HighCVE-2026-60792026-08-05
Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion
HighCVE-2026-166232026-08-04
Create Block Theme < 2.10.0 – Admin+ PHP Code Injection via Pattern Save (Multisite) | CVE 2026-16623 | Plugin Vulnerabi
MediumCVE-2026-165472026-08-04
REST API Log < 1.7.1 – Unauthenticated Sensitive Log Data Disclosure via Download Endpoint | CVE 2026-16547 | Plugin Vul
MediumCVE-2026-148722026-08-04
Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 – Authenticated SQL Injection via id Parameter | CVE 2026-
HighCVE-2026-159312026-08-03
Simple Membership < 4.7.8 – Unauthenticated Stored XSS via PayPal Subscription Subscriber Name | CVE 2026-15931 | Plugin
HighCVE-2026-160602026-08-03
Insert or Embed Articulate Content into WordPress <= 4.3000000027 – Editor+ Arbitrary File Upload | CVE 2026-16060 | Plu
HighCVE-2026-165322026-08-03
Link Library < 7.9.3 – Unauthenticated SQL Injection via the Front-End Link Submission Form | CVE 2026-16532 | Plugin Vu
MediumCVE-2025-156732026-08-03
Import and export users and customers < 2.4.3 – Admin+ Arbitrary File Read | CVE 2025-15673 | Plugin Vulnerabilities
HighCVE-2026-183522026-08-02
User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
MediumCVE-2026-150182026-08-02
Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-collation-algorithm' Parameter

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with WordPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.