Vendor
WordPress.org vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in WordPress.org: 6 in the last 7 days and 19 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96752, was published on 25 September 2026.
- Last 7 days
- 6
- Last 90 days
- 19
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest WordPress.org vulnerabilities
- CVE-2026-96752: Zero Spam for WordPress stored XSS in Contact Form 7highCVSS 7.2EPSS 0.2%
- CVE-2026-94573: Repeater Fields for Elementor Forms stored cross-site scriptinghighCVSS 7.2EPSS 0.2%
- CVE-2026-96766: GeoDirectory stored cross-site scripting in business_hours parametermediumCVSS 6.4EPSS 0.2%
- CVE-2026-86583: Import and export users and customers plugin privilege escalationhighCVSS 8.8EPSS 0.3%
- CVE-2026-93510: Points and Rewards for WooCommerce arbitrary points manipulationmediumCVSS 4.3EPSS 0.1%
- CVE-2026-93778: WP Yelp Review Slider stored cross-site scripting in review texthighCVSS 7.2EPSS 0.4%
- CVE-2026-15660: WordPress SEO Booster plugin missing authorization checksmediumCVSS 4.3EPSS 0.2%
- CVE-2026-88910: WordPress kboard plugin unauthenticated media deletion via IDORmediumCVSS 5.3EPSS 0.3%
- CVE-2026-11996: WordPress Advanced Popups plugin stored cross-site scriptingmediumCVSS 6.4EPSS 0.2%
- CVE-2026-18063: WordPress Job Postings plugin stored cross-site scriptingmediumCVSS 6.4EPSS 0.2%
- CVE-2026-16502: Live Composer PHP Object Injection via deserializationhighCVSS 8.8EPSS 0.4%
- CVE-2026-4945: Otter Blocks Insecure Direct Object Reference in checkoutmediumCVSS 5.3EPSS 0.4%
- CVE-2026-80439: Redirection for Contact Form 7 arbitrary shortcode executionmediumCVSS 4.8EPSS 0.2%
- CVE-2026-78149: WordPress Post Carousel plugin unauthenticated password disclosuremediumCVSS 5.3EPSS 0.4%
- CVE-2026-16983: WordPress Gutentor plugin password disclosure via REST APImediumCVSS 4.3EPSS 0.2%
- CVE-2026-74020: Koji WordPress Theme broken access controlhighCVSS 7.5EPSS 0.4%
- CVE-2026-66594: WordPress Persistent Login SQL injection in subscriber rolehighCVSS 8.5EPSS 0.4%
- CVE-2026-19615: WordPress Admin and Site Enhancements stored XSS via SVG uploadmediumCVSS 6.8EPSS 0.4%
- CVE-2026-15939: Simple Restrict authorization bypass in REST APIlowCVSS 2.7EPSS 0.3%
Most severe WordPress.org vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-16502: Live Composer PHP Object Injection via deserializationhighCVSS 8.8EPSS 0.4%
- CVE-2026-86583: Import and export users and customers plugin privilege escalationhighCVSS 8.8EPSS 0.3%
- CVE-2026-66594: WordPress Persistent Login SQL injection in subscriber rolehighCVSS 8.5EPSS 0.4%
- CVE-2026-74020: Koji WordPress Theme broken access controlhighCVSS 7.5EPSS 0.4%
- CVE-2026-93778: WP Yelp Review Slider stored cross-site scripting in review texthighCVSS 7.2EPSS 0.4%
- CVE-2026-96752: Zero Spam for WordPress stored XSS in Contact Form 7highCVSS 7.2EPSS 0.2%
- CVE-2026-94573: Repeater Fields for Elementor Forms stored cross-site scriptinghighCVSS 7.2EPSS 0.2%
- CVE-2026-19615: WordPress Admin and Site Enhancements stored XSS via SVG uploadmediumCVSS 6.8EPSS 0.4%
- CVE-2026-11996: WordPress Advanced Popups plugin stored cross-site scriptingmediumCVSS 6.4EPSS 0.2%
- CVE-2026-96766: GeoDirectory stored cross-site scripting in business_hours parametermediumCVSS 6.4EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 6 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/wordpress-org.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "WordPress.org vulnerabilities", https://junglewise.ai/threats/vendors/wordpress-org, 26 September 2026.