WordPress represents one of the most widely deployed content-management platforms in the landscape, with a footprint spanning the core system, multisite variants, and a vast ecosystem of plugins, creating an exceptionally large attack surface. Vulnerabilities affecting the platform and its plugin ecosystem frequently acquire public exploit code, reflecting the accessibility and ubiquity of WordPress deployments and the relative ease of exploitation for the durable weakness classes that recur across its products. The recurring exposure centers on input-handling flaws including cross-site scripting, SQL injection, and cross-site request forgery, alongside a category of less-specific weaknesses typical of plugin and third-party extension disclosures, and reflects the inherent risks of a widely extensible platform with distributed development and variable security practices across the plugin community. Defenders should treat WordPress installations as high-maintenance assets requiring aggressive patching discipline, security plugin deployment, and staged updates across theme and plugin dependencies; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wordpress over time
Signals from CVEs in this vendor scope (633 CVEs).
633 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10033CRITICAL The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrar | Dec 30, 2016 | 9.8 | 99 | YES | YES |
CVE-2026-63030CRITICAL WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C | Jul 17, 2026 | 9.8 | 96 | YES | YES |
CVE-2016-10045CRITICAL The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging impr | Dec 30, 2016 | 9.8 | 91 | NO | YES |
CVE-2026-60137CRITICAL WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a | Jul 17, 2026 | 9.1 | 89 | YES | NO |
CVE-2022-21661HIGH WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where | Jan 6, 2022 | 7.5 | 89 | NO | YES |
CVE-2019-8943MEDIUM WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filen | Feb 20, 2019 | 6.5 | 89 | NO | YES |
CVE-2019-8942HIGH WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with | Feb 20, 2019 | 8.8 | 85 | NO | YES |
CVE-2023-2745MEDIUM WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arb | May 17, 2023 | 6.1 | 81 | NO | YES |
CVE-2021-29447MEDIUM Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This require | Apr 15, 2021 | 6.5 | 79 | NO | YES |
CVE-2017-1001000HIGH The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identi | Apr 3, 2017 | 7.5 | 79 | NO | YES |
Signals from CVEs in this vendor scope (633 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wordpress.
Media articles that mention a CVE ID that affects a product developed by Wordpress — matched by CVE ID, not by vendor name.