WordPress records
665 published records for vendor wordpress.
Researcher profile
- Entered KEV
- 4 · 0.6%
- Weaponized
- 15 · 2.3%
- Pre-auth RCE
- 101
- With a fix record
- 53.2%
- Median publish → KEV
- 4 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')235
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')58
- CWE-352 Cross-Site Request Forgery (CSRF)53
- CWE-264 Permissions, Privileges, and Access Controls41
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation24
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
665 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2016-10033Weaponized | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Critical9.8 | KEV | 99.7% | Dec 30, 2016 |
72This week | CVE-2026-63030Weaponized | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Executionwordpress · wordpress · CWE-436 | Critical9.8 | KEV | 10.1% | Jul 17, 2026 |
68This week | CVE-2016-10045Weaponized | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently ephpmailer project · phpmailer · CWE-77 | Critical9.8 | — | 97.7% | Dec 30, 2016 |
68This week | CVE-2026-87902Weaponized | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | High8.1 | KEV | 19.8% | Sep 22, 2026 |
60This week | CVE-2019-8942Weaponized | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an awordpress · wordpress · CWE-434 | High8.8 | — | 82.7% | Feb 19, 2019 |
59Plan | CVE-2022-21661Proof of concept | SQL injection in WordPresswordpress · wordpress · CWE-89 | High7.5 | — | 97.8% | Jan 6, 2022 |
55Plan | CVE-2017-1001000Weaponized | The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before wordpress · wordpress | High7.5 | — | 84.9% | Apr 2, 2017 |
55Plan | CVE-2026-60137Weaponized | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Querywordpress · wordpress · CWE-89 | Medium5.9 | KEV | 5.9% | Jul 17, 2026 |
54Plan | CVE-2019-8943Weaponized | WordPress through 5.0.3 allows Path Traversal in wp_crop_image().wordpress · wordpress · CWE-22 | Medium6.5 | — | 92.6% | Feb 19, 2019 |
54Plan | CVE-2018-12895Weaponized | WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb paramwordpress · wordpress · CWE-22 | High8.8 | — | 62.2% | Jun 26, 2018 |
52Plan | CVE-2021-29447Proof of concept | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Medium6.5 | — | 85.7% | Apr 15, 2021 |
52Plan | CVE-2018-6389Proof of concept | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | High7.5 | — | 72.7% | Feb 6, 2018 |
48Plan | CVE-2021-44223No exploit | WordPress before 5.8 lacks support for the Update URI plugin header.wordpress · wordpress | Critical9.8 | — | 29.0% | Nov 25, 2021 |
47Plan | CVE-2017-5487Proof of concept | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not propwordpress · wordpress · CWE-200 | Medium5.3 | — | 87.3% | Jan 14, 2017 |
47Plan | CVE-2019-9787Proof of concept | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default confwordpress · wordpress · CWE-352 | High8.8 | — | 38.7% | Mar 14, 2019 |
47Plan | CVE-2018-20148Proof of concept | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediwordpress · wordpress · CWE-502 | Critical9.8 | — | 26.8% | Dec 14, 2018 |
46Plan | CVE-2009-2335Weaponized | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Medium5.0 | — | 85.0% | Jul 10, 2009 |
46Plan | CVE-2012-3576Proof of concept | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to exwordpress · wordpress · CWE-264 | Critical10.0 | — | 18.4% | Jun 15, 2012 |
45Plan | CVE-2014-9034Proof of concept | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Medium5.0 | — | 82.7% | Nov 25, 2014 |
45Plan | CVE-2023-2745Proof of concept | WordPress Core < 6.2.1 - Directory Traversalwordpress · wordpress · CWE-22 | Medium5.4 | — | 79.5% | May 17, 2023 |
45Plan | CVE-2024-4439Proof of concept | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Medium6.1 | — | 71.0% | May 3, 2024 |
45Plan | CVE-2008-3362Proof of concept | Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackegiulio ganci · wp downloads manager · CWE-20 | Critical10.0 | — | 16.8% | Jul 30, 2008 |
45Plan | CVE-2012-3575Proof of concept | Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrrbx gallery · rbx gallery · CWE-264 | Critical10.0 | — | 15.4% | Jun 15, 2012 |
44Plan | CVE-2008-1059Proof of concept | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote awordpress · sniplets plugin · CWE-94 | High7.5 | — | 48.3% | Feb 28, 2008 |
44Plan | CVE-2020-28032Proof of concept | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.wordpress · wordpress · CWE-502 | Critical9.8 | — | 16.1% | Nov 2, 2020 |
- CVE-2016-1003399Now
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
CriticalCVSS 9.8KEVWeaponizedEPSS 100%phpmailer project · phpmailerDec 30, 2016
- CVE-2026-6303072This week
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CriticalCVSS 9.8KEVWeaponizedEPSS 10%wordpress · wordpressJul 17, 2026
- CVE-2016-1004568This week
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e
CriticalCVSS 9.8WeaponizedEPSS 98%phpmailer project · phpmailerDec 30, 2016
- CVE-2026-8790268This week
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
HighCVSS 8.1KEVWeaponizedEPSS 20%wordpress · wordpressSep 22, 2026
- CVE-2019-894260This week
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a
HighCVSS 8.8WeaponizedEPSS 83%wordpress · wordpressFeb 19, 2019
- CVE-2022-2166159Plan
SQL injection in WordPress
HighCVSS 7.5Proof of conceptEPSS 98%wordpress · wordpressJan 6, 2022
- CVE-2017-100100055Plan
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before
HighCVSS 7.5WeaponizedEPSS 85%wordpress · wordpressApr 2, 2017
- CVE-2026-6013755Plan
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
MediumCVSS 5.9KEVWeaponizedEPSS 6%wordpress · wordpressJul 17, 2026
- CVE-2019-894354Plan
WordPress through 5.0.3 allows Path Traversal in wp_crop_image().
MediumCVSS 6.5WeaponizedEPSS 93%wordpress · wordpressFeb 19, 2019
- CVE-2018-1289554Plan
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param
HighCVSS 8.8WeaponizedEPSS 62%wordpress · wordpressJun 26, 2018
- CVE-2021-2944752Plan
WordPress Authenticated XXE attack when installation is running PHP 8
MediumCVSS 6.5Proof of conceptEPSS 86%wordpress · wordpressApr 15, 2021
- CVE-2018-638952Plan
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
HighCVSS 7.5Proof of conceptEPSS 73%wordpress · wordpressFeb 6, 2018
- CVE-2021-4422348Plan
WordPress before 5.8 lacks support for the Update URI plugin header.
CriticalCVSS 9.8No exploitEPSS 29%wordpress · wordpressNov 25, 2021
- CVE-2017-548747Plan
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop
MediumCVSS 5.3Proof of conceptEPSS 87%wordpress · wordpressJan 14, 2017
- CVE-2019-978747Plan
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
HighCVSS 8.8Proof of conceptEPSS 39%wordpress · wordpressMar 14, 2019
- CVE-2018-2014847Plan
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi
CriticalCVSS 9.8Proof of conceptEPSS 27%wordpress · wordpressDec 14, 2018
- CVE-2009-233546Plan
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
MediumCVSS 5.0WeaponizedEPSS 85%wordpress · wordpressJul 10, 2009
- CVE-2012-357646Plan
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex
CriticalCVSS 10.0Proof of conceptEPSS 18%wordpress · wordpressJun 15, 2012
- CVE-2014-903445Plan
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
MediumCVSS 5.0Proof of conceptEPSS 83%wordpress · wordpressNov 25, 2014
- CVE-2023-274545Plan
WordPress Core < 6.2.1 - Directory Traversal
MediumCVSS 5.4Proof of conceptEPSS 80%wordpress · wordpressMay 17, 2023
- CVE-2024-443945Plan
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
MediumCVSS 6.1Proof of conceptEPSS 71%wordpress · wordpressMay 3, 2024
- CVE-2008-336245Plan
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke
CriticalCVSS 10.0Proof of conceptEPSS 17%giulio ganci · wp downloads managerJul 30, 2008
- CVE-2012-357545Plan
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr
CriticalCVSS 10.0Proof of conceptEPSS 15%rbx gallery · rbx galleryJun 15, 2012
- CVE-2008-105944Plan
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a
HighCVSS 7.5Proof of conceptEPSS 48%wordpress · sniplets pluginFeb 28, 2008
- CVE-2020-2803244Plan
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CriticalCVSS 9.8Proof of conceptEPSS 16%wordpress · wordpressNov 2, 2020