Vendor
Wordpress vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 112 vulnerabilities in Wordpress: 1 in the last 7 days and 49 in the last 90 days, 16 of them critical and 6 exploited in the wild. The most recent, CVE-2026-87902, was published on 22 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 49
- Critical, all time
- 16
- Exploited in the wild
- 6
About Wordpress
WordPress is an open-source content management system based on PHP and MySQL.
Wordpress technologies
Latest Wordpress vulnerabilities
- CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php`…criticalexploited in the wildCVSS 8.1EPSS 2.9%
- CVE-2026-89138: WordPress Filter Gallery authorization bypassmediumCVSS 4.3EPSS 0.4%
- CVE-2026-12106: WordPress Auto Upload Images limited server-side request forgerymediumCVSS 6.4EPSS 0.3%
- CVE-2026-90978: WordPress Filter Gallery nonce verification bypass in AJAX handlershighCVSS 7.1EPSS 0.3%
- CVE-2026-88993: All Bootstrap Blocks stored XSS in block attributemediumCVSS 6.8EPSS 0.4%
- CVE-2026-87771: Product Question and Answer SQL injectionhighCVSS 8.6EPSS 0.4%
- CVE-2026-16750: The Motors Car Dealership and Classified Listings Plugin authorization bypassmediumCVSS 5.3EPSS 0.2%
- CVE-2026-16582: Booking for Appointments and Events Calendar , Amelia authorization bypass in payment validationmediumCVSS 5.3EPSS 0.2%
- CVE-2026-86801: WordPress To Do List Member plugin unauthenticated file upload and XSShighCVSS 8.8EPSS 0.5%
- CVE-2026-87935: WordPress Paid Downloads arbitrary file uploadhighCVSS 8.1EPSS 0.9%
- CVE-2026-85681: WP Component WordPress plugin unauthenticated privilege escalationcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-14563: WordPress Advanced Customized Prompts authentication bypasscriticalCVSS 9.8EPSS 0.3%
- CVE-2026-14560: WordPress Teddy Bear Customize Addon arbitrary file uploadcriticalCVSS 10EPSS 0.4%
- CVE-2026-81754: WordPress The Vigilant plugin stored XSS via User-Agent headerhighCVSS 7.2EPSS 0.4%
- CVE-2026-18964: WordPress Chaty plugin reflected XSS via search parametermediumCVSS 6.1EPSS 0.2%
- CVE-2026-15462: Sticky Chat Widget SQL injection via form field parametershighCVSS 7.5EPSS 0.3%
- CVE-2026-81800: Verified Reviews (Avis Vérifiés) unauthenticated SQL injectioncriticalCVSS 9.3EPSS 0.4%
- CVE-2026-81795: WordPress Page Visits Counter , Lite unauthenticated XSShighCVSS 7.1EPSS 0.3%
- CVE-2026-81794: Shirt Product Designer for WooCommerce broken access controlhighCVSS 7.5EPSS 0.4%
- CVE-2026-81782: WordPress WP Docs cross-site scripting in pluginmediumCVSS 6.5EPSS 0.2%
- CVE-2026-14873: WordPress Bulk Password Reset privilege escalation via account takeoverhighCVSS 8EPSS 0.2%
- CVE-2026-85117: Contact Form 7 Captcha arbitrary shortcode executionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-4357: WordPress Embed HTML5 Game plugin unauthenticated file uploadcriticalCVSS 10EPSS 0.5%
- CVE-2025-9314: WordPress Developer Tools plugin unauthenticated arbitrary file upload in SWFUploadcriticalCVSS 9.8EPSS 0.3%
- CVE-2026-17589: WordPress Shopping Cart & eCommerce Store SQL Injection in product_ordermediumCVSS 4.9EPSS 0.3%
Most severe Wordpress vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-25213: WordPress File Manager Plugin Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-60137: WordPress SQL injection in WP_Query author__not_in parametercriticalexploited in the wildCVSS 9.1EPSS 4.0%
- CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php`…criticalexploited in the wildCVSS 8.1EPSS 2.9%
- CVE-2026-63030: WordPress REST API route confusion and SQL injection leading to RCEcriticalexploited in the wildCVSS 7.5EPSS 8.9%
- CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2019-9978: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerabilitycriticalexploited in the wildCVSS 6.1
- CVE-2026-4357: WordPress Embed HTML5 Game plugin unauthenticated file uploadcriticalCVSS 10EPSS 0.5%
- CVE-2026-14560: WordPress Teddy Bear Customize Addon arbitrary file uploadcriticalCVSS 10EPSS 0.4%
- CVE-2026-85681: WP Component WordPress plugin unauthenticated privilege escalationcriticalCVSS 9.8EPSS 0.5%
- CVE-2025-15689: WordPress Capella Theme privilege escalationcriticalCVSS 9.8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 2 | 2 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 6 | 1 | |
| 10 Aug 2026 | 4 | 0 | |
| 17 Aug 2026 | 7 | 1 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 3 | 2 | |
| 7 Sep 2026 | 12 | 4 | |
| 14 Sep 2026 | 9 | 0 | |
| 21 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/wordpress.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Wordpress vulnerabilities", https://junglewise.ai/threats/vendors/wordpress, 26 September 2026.