Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WordPress — Vulnerabilities & Security Advisories 39

Browse all 39 CVE security advisories affecting WordPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WordPress operates as an open-source content management system powering a significant portion of the global web, primarily enabling users to create and manage websites without extensive coding knowledge. Its widespread adoption has made it a frequent target for attackers, resulting in thirty-two recorded Common Vulnerabilities and Exposures. Historically, the platform has been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insecure plugin architectures or insufficient input validation. Security incidents frequently involve unauthorized administrative access or data exfiltration through exploited themes and extensions. While the core software undergoes rigorous review, the extensive ecosystem of third-party contributions introduces variability in security hygiene. Regular updates and strict adherence to security best practices are essential for mitigating risks associated with its complex, modular structure and high visibility in the digital landscape.

CVE ID Title CVSS Severity Published
CVE-2026-87902 WordPress 6.7.1 get_page_template 本地文件包含 — WordPress CWE-98 - - 2026-09-22
CVE-2026-65640 WordPress 任意文件上传漏洞 — WordPress CWE-434 - - 2026-08-17
CVE-2026-64638 WordPress 跨站脚本漏洞 — WordPress CWE-79 8.9 High 2026-08-07
CVE-2026-45293 WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability — WordPress-Coding-Standards CWE-95 8.6 High 2026-07-28
CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution — WordPress 9.8 Critical 2026-07-17
CVE-2026-60137 WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query — WordPress 5.9 Medium 2026-07-17
CVE-2020-37233 WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting — Buddypress CWE-79 6.4 Medium 2026-05-16
CVE-2023-54333 Social-Share-Buttons 2.2.3 - SQL Injection via project_id Parameter — Social-Share-Buttons CWE-89 8.2 High 2026-01-13
CVE-2025-58674 WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability — WordPress CWE-79 5.9 Medium 2025-09-23
CVE-2025-58246 WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability — WordPress CWE-201 4.3 Medium 2025-09-23
CVE-2025-54352 WordPress 安全漏洞 — WordPress CWE-669 3.7 Low 2025-07-21
CVE-2024-31211 Remote Code Execution in `WP_HTML_Token` — wordpress-develop CWE-502 5.5 Medium 2024-04-04
CVE-2024-31210 PHP file upload bypass via Plugin installer — wordpress-develop CWE-434 7.7 High 2024-04-04
CVE-2023-5561 WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure — WordPress 5.3 - 2023-10-16
CVE-2022-3590 WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding — WordPress 5.9 - 2022-12-14
CVE-2022-21662 Stored XSS in WordPress — wordpress-develop CWE-79 8.0 High 2022-01-06
CVE-2022-21663 Authenticated Object Injection in Multisites in WordPress — wordpress-develop CWE-74 6.6 Medium 2022-01-06
CVE-2022-21664 SQL injection in WordPress — wordpress-develop CWE-89 7.4 High 2022-01-06
CVE-2022-21661 SQL injection in WordPress — wordpress-develop CWE-89 8.0 High 2022-01-06
CVE-2021-39203 Private data disclosure/privilege escalation through the block editor in Wordpress — wordpress-develop CWE-200 6.8 Medium 2021-09-09
CVE-2021-39202 WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget — wordpress-develop CWE-79 7.6 High 2021-09-09
CVE-2021-39201 Authenticated cross-site scripting (XSS) in WordPress editor — wordpress-develop CWE-79 7.6 High 2021-09-09
CVE-2021-39200 Information Disclosure in wp_die() via JSONP in wordpress — wordpress-develop CWE-200 5.3 Medium 2021-09-09
CVE-2021-29476 Insecure Deserialization of untrusted data in rmccue/requests — Requests CWE-502 9.8 Critical 2021-04-27
CVE-2021-29450 WordPress Authenticated disclosure of password-protected posts and pages — wordpress-develop CWE-200 6.5 Medium 2021-04-15
CVE-2021-29447 WordPress Authenticated XXE attack when installation is running PHP 8 — wordpress-develop CWE-611 7.1 High 2021-04-15
CVE-2020-4047 Authenticated XSS via media attachment page in WordPress — wordpress-develop CWE-80 6.8 Medium 2020-06-12
CVE-2020-4048 Open redirect in wp_validate_redirect() in WordPress — wordpress-develop CWE-601 5.7 Medium 2020-06-12
CVE-2020-4049 Authenticated self-XSS via theme uploads in WordPress — wordpress-develop CWE-80 2.4 Low 2020-06-12
CVE-2020-4050 set-screen-option filter misuse by plugins leading to privilege escalation in WordPress — wordpress-develop CWE-288 3.5 Low 2020-06-12

This page lists every published CVE security advisory associated with WordPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.