← WordPress Vulnerabilities
WordPress security by component

WordPress core

45 known core vulnerabilities, newest first.

Safe version
Jul 17, 2026 CVE-2026-63030
WordPress REST batch-route confusion can lead to remote code execution
A route-confusion weakness in the WordPress REST batch endpoint can be combined with the author__not_in SQL injection tracked as CVE-2026-60137. On affected WordPress 6.9 and 7.0 releases, an unauthenticated request can turn that chain into database compromise and potentially remote code execution.
6.9.5, 7.0.2
CVE9.8
NVDPending
Jul 17, 2026 CVE-2026-60137
WordPress WP_Query author exclusion can permit SQL injection
Affected WordPress core releases do not safely handle author__not_in when untrusted input reaches WP_Query. The flaw becomes directly exploitable when a plugin, theme, or REST route forwards attacker-controlled values into that argument, and it is one half of the critical remote-code-execution chain tracked separately as CVE-2026-63030.
6.8.6, 6.9.5, 7.0.2
CVE5.9
NVDPending
Mar 11, 2026 CVE-2026-3906
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 23, 2025 CVE-2025-58674
WordPress: Cross-site scripting
WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Sep 23, 2025 CVE-2025-58246
WordPress: A security weakness
WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 21, 2025 CVE-2025-54352
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.7
NVDPending
Oct 16, 2024 CVE-2022-4973
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.9
NVD5.4
Jun 25, 2024 CVE-2024-32111
WordPress: Filesystem traversal
WordPress is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.0
NVDPending
Jun 25, 2024 CVE-2024-31111
WordPress: Cross-site scripting
WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jun 25, 2024 CVE-2024-6307
various: Cross-site scripting
various is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 03, 2024 CVE-2024-4439
the Avatar block in various: Cross-site scripting
the Avatar block in various is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Apr 05, 2024 CVE-2023-5692
WordPress component: Sensitive information exposure
WordPress component is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Oct 13, 2023 CVE-2023-39999
WordPress: A security weakness
WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 17, 2023 CVE-2023-2745
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD6.1
Jan 06, 2022 CVE-2022-21662
WordPress: Cross-site scripting
WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE8.0
NVD5.4
Jan 06, 2022 CVE-2022-21661
WordPress: SQL injection
WordPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.0
NVD7.5
Apr 03, 2017 CVE-2017-1001000
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jan 15, 2017 CVE-2017-5487
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 18, 2014 CVE-2014-5203
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jul 22, 2012 CVE-2012-3383
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE2.6
NVD2.6
Sep 24, 2011 CVE-2011-3818
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0
Aug 10, 2011 CVE-2011-3130
WordPress component: SQL injection
WordPress component is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Aug 10, 2011 CVE-2011-3129
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.3
NVD9.3
Aug 10, 2011 CVE-2011-3128
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0
Aug 10, 2011 CVE-2011-3127
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVD5.8
Aug 10, 2011 CVE-2011-3126
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0
Aug 10, 2011 CVE-2011-3125
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE10.0
NVD10.0
Aug 10, 2011 CVE-2011-3122
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE10.0
NVD10.0
Feb 23, 2010 CVE-2010-0682
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.0
NVD4.0
May 21, 2008 CVE-2008-2392
WordPress 2.5.1 and earlier might: A security weakness
WordPress 2.5.1 and earlier might is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.0
NVD9.0
May 02, 2008 CVE-2008-2068
WordPress 2.5: Cross-site scripting
WordPress 2.5 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Mar 12, 2008 CVE-2008-1304
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Jan 10, 2008 CVE-2008-0196
WordPress component: Filesystem traversal
WordPress component is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.0
NVD5.0
Jan 10, 2008 CVE-2008-0192
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Jan 10, 2008 CVE-2008-0191
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0
Nov 19, 2007 CVE-2007-6013
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Sep 26, 2007 CVE-2007-5105
wp-register.php in WordPress 2.0 and 2.0.1: Cross-site scripting
wp-register.php in WordPress 2.0 and 2.0.1 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Aug 03, 2007 CVE-2007-4153
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE2.1
NVD2.1
Feb 21, 2007 CVE-2007-1049
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Sep 13, 2006 CVE-2006-4743
WordPress component: A security weakness
WordPress component is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0
May 30, 2006 CVE-2006-2667
WordPress 2.0.2 and earlier: Code execution
WordPress 2.0.2 and earlier is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD7.5
Mar 06, 2006 CVE-2006-1012
WordPress 1.5.2, and possibly other versions before 2.0,: SQL injection
WordPress 1.5.2, and possibly other versions before 2.0, is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Feb 16, 2006 CVE-2006-0733
WordPress 2.0.0: Cross-site scripting
WordPress 2.0.0 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE2.6
NVD2.6
Aug 17, 2005 CVE-2005-2612
WordPress 1.5.1.3 and earlier: Code execution
WordPress 1.5.1.3 and earlier is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD7.5
Dec 31, 2004 CVE-2004-1559
WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3