Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wordpress

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 633
61.6
VTI Score
TOP TARGET

WordPress represents one of the most widely deployed content-management platforms in the landscape, with a footprint spanning the core system, multisite variants, and a vast ecosystem of plugins, creating an exceptionally large attack surface. Vulnerabilities affecting the platform and its plugin ecosystem frequently acquire public exploit code, reflecting the accessibility and ubiquity of WordPress deployments and the relative ease of exploitation for the durable weakness classes that recur across its products. The recurring exposure centers on input-handling flaws including cross-site scripting, SQL injection, and cross-site request forgery, alongside a category of less-specific weaknesses typical of plugin and third-party extension disclosures, and reflects the inherent risks of a widely extensible platform with distributed development and variable security practices across the plugin community. Defenders should treat WordPress installations as high-maintenance assets requiring aggressive patching discipline, security plugin deployment, and staged updates across theme and plugin dependencies; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
633
Total CVEs
More Total CVEs than 100% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Wordpress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Products(51 total)

Top CVEs

Signals from CVEs in this vendor scope (633 CVEs).

633 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10033CRITICAL
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrar
Dec 30, 20169.899YESYES
CVE-2026-63030CRITICAL
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C
Jul 17, 20269.896YESYES
CVE-2016-10045CRITICAL
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging impr
Dec 30, 20169.891NOYES
CVE-2026-60137CRITICAL
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a
Jul 17, 20269.189YESNO
CVE-2022-21661HIGH
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where
Jan 6, 20227.589NOYES
CVE-2019-8943MEDIUM
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filen
Feb 20, 20196.589NOYES
CVE-2019-8942HIGH
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with
Feb 20, 20198.885NOYES
CVE-2023-2745MEDIUM
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arb
May 17, 20236.181NOYES
CVE-2021-29447MEDIUM
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This require
Apr 15, 20216.579NOYES
CVE-2017-1001000HIGH
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identi
Apr 3, 20177.579NOYES
View all 633 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products633 CVEs
68%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network174 (27.5%)
Unknown458 (72.4%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low167 (26.4%)
High8 (1.3%)
Unknown458 (72.4%)
User Interaction
None91 (14.4%)
Unknown458 (72.4%)
Required84 (13.3%)
Privileges Required
Low53 (8.4%)
High6 (0.9%)
None116 (18.3%)
Unknown458 (72.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (633 CVEs).

CISA KEV
3 CVEs
0.5% of CVEs· 99th percentile
Metasploit
12 CVEs
1.9% of CVEs· 97th percentile
Nuclei
32 CVEs
5.1% of CVEs· 96th percentile
ExploitDB
185 CVEs
29.2% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wordpress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wordpress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wordpress's Products

View all 10 CNAs →

Top CWEs