{"schema_version":1,"title":"WordPress.org vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in WordPress.org: 6 in the last 7 days and 19 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96752, was published on 25 September 2026.","url":"https://junglewise.ai/threats/vendors/wordpress-org","json_url":"https://junglewise.ai/threats/vendors/wordpress-org.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/wordpress-org","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":7,"all_time":19,"critical":0,"exploited":0,"last_7_days":6,"last_30_days":15,"last_90_days":19,"last_365_days":19},"latest":[{"cve":"CVE-2026-96752","cvss":7.2,"epss":0.0024,"slug":"cve-2026-96752-the-zero-spam-for-wordpress-plugin-for-wordpress-is-vulnerable-to","title":"Zero Spam for WordPress stored XSS in Contact Form 7","severity":"high","exploited":false,"published_at":"2026-09-25T08:16:42.7+00:00","url":"https://junglewise.ai/threats/cve-2026-96752-the-zero-spam-for-wordpress-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-94573","cvss":7.2,"epss":0.0024,"slug":"cve-2026-94573-the-repeater-fields-for-elementor-forms-plugin-for-wordpress-is","title":"Repeater Fields for Elementor Forms stored cross-site scripting","severity":"high","exploited":false,"published_at":"2026-09-25T08:16:42.047+00:00","url":"https://junglewise.ai/threats/cve-2026-94573-the-repeater-fields-for-elementor-forms-plugin-for-wordpress-is"},{"cve":"CVE-2026-96766","cvss":6.4,"epss":0.002,"slug":"cve-2026-96766-the-geodirectory-wp-business-directory-plugin-and-classified","title":"GeoDirectory stored cross-site scripting in business_hours parameter","severity":"medium","exploited":false,"published_at":"2026-09-25T07:16:57.017+00:00","url":"https://junglewise.ai/threats/cve-2026-96766-the-geodirectory-wp-business-directory-plugin-and-classified"},{"cve":"CVE-2026-86583","cvss":8.8,"epss":0.0033,"slug":"cve-2026-86583-the-import-and-export-users-and-customers-plugin-for-wordpress-is","title":"Import and export users and customers plugin privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-23T22:16:59.22+00:00","url":"https://junglewise.ai/threats/cve-2026-86583-the-import-and-export-users-and-customers-plugin-for-wordpress-is"},{"cve":"CVE-2026-93510","cvss":4.3,"epss":0.0015,"slug":"cve-2026-93510-the-points-and-rewards-for-woocommerce-wordpress-plugin-before-2","title":"Points and Rewards for WooCommerce arbitrary points manipulation","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:06.057+00:00","url":"https://junglewise.ai/threats/cve-2026-93510-the-points-and-rewards-for-woocommerce-wordpress-plugin-before-2"},{"cve":"CVE-2026-93778","cvss":7.2,"epss":0.0043,"slug":"cve-2026-93778-the-wp-yelp-review-slider-plugin-for-wordpress-is-vulnerable-to","title":"WP Yelp Review Slider stored cross-site scripting in review text","severity":"high","exploited":false,"published_at":"2026-09-22T08:16:42.767+00:00","url":"https://junglewise.ai/threats/cve-2026-93778-the-wp-yelp-review-slider-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-15660","cvss":4.3,"epss":0.002,"slug":"cve-2026-15660-the-seo-booster-plugin-for-wordpress-is-vulnerable-to-missing","title":"WordPress SEO Booster plugin missing authorization checks","severity":"medium","exploited":false,"published_at":"2026-09-19T03:17:13.717+00:00","url":"https://junglewise.ai/threats/cve-2026-15660-the-seo-booster-plugin-for-wordpress-is-vulnerable-to-missing"},{"cve":"CVE-2026-88910","cvss":5.3,"epss":0.003,"slug":"cve-2026-88910-wordpress-kboard-plugin-unauthenticated-media-deletion-via-idor","title":"WordPress kboard plugin unauthenticated media deletion via IDOR","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:35.707+00:00","url":"https://junglewise.ai/threats/cve-2026-88910-wordpress-kboard-plugin-unauthenticated-media-deletion-via-idor"},{"cve":"CVE-2026-11996","cvss":6.4,"epss":0.0021,"slug":"cve-2026-11996-wordpress-advanced-popups-plugin-stored-cross-site-scripting","title":"WordPress Advanced Popups plugin stored cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-16T04:17:53.683+00:00","url":"https://junglewise.ai/threats/cve-2026-11996-wordpress-advanced-popups-plugin-stored-cross-site-scripting"},{"cve":"CVE-2026-18063","cvss":6.4,"epss":0.002,"slug":"cve-2026-18063-wordpress-job-postings-plugin-stored-cross-site-scripting","title":"WordPress Job Postings plugin stored cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-15T07:16:26.757+00:00","url":"https://junglewise.ai/threats/cve-2026-18063-wordpress-job-postings-plugin-stored-cross-site-scripting"},{"cve":"CVE-2026-16502","cvss":8.8,"epss":0.0045,"slug":"cve-2026-16502-live-composer-php-object-injection-via-deserialization","title":"Live Composer PHP Object Injection via deserialization","severity":"high","exploited":false,"published_at":"2026-09-08T12:16:52.443+00:00","url":"https://junglewise.ai/threats/cve-2026-16502-live-composer-php-object-injection-via-deserialization"},{"cve":"CVE-2026-4945","cvss":5.3,"epss":0.0039,"slug":"cve-2026-4945-otter-blocks-insecure-direct-object-reference-in-checkout","title":"Otter Blocks Insecure Direct Object Reference in checkout","severity":"medium","exploited":false,"published_at":"2026-09-07T13:20:22.07+00:00","url":"https://junglewise.ai/threats/cve-2026-4945-otter-blocks-insecure-direct-object-reference-in-checkout"},{"cve":"CVE-2026-80439","cvss":4.8,"epss":0.0024,"slug":"cve-2026-80439-redirection-for-contact-form-7-arbitrary-shortcode-execution","title":"Redirection for Contact Form 7 arbitrary shortcode execution","severity":"medium","exploited":false,"published_at":"2026-09-06T10:17:14.81+00:00","url":"https://junglewise.ai/threats/cve-2026-80439-redirection-for-contact-form-7-arbitrary-shortcode-execution"},{"cve":"CVE-2026-78149","cvss":5.3,"epss":0.0035,"slug":"cve-2026-78149-wordpress-post-carousel-plugin-unauthenticated-password","title":"WordPress Post Carousel plugin unauthenticated password disclosure","severity":"medium","exploited":false,"published_at":"2026-09-05T07:17:12.3+00:00","url":"https://junglewise.ai/threats/cve-2026-78149-wordpress-post-carousel-plugin-unauthenticated-password"},{"cve":"CVE-2026-16983","cvss":4.3,"epss":0.0021,"slug":"cve-2026-16983-wordpress-gutentor-plugin-password-disclosure-via-rest-api","title":"WordPress Gutentor plugin password disclosure via REST API","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:16.547+00:00","url":"https://junglewise.ai/threats/cve-2026-16983-wordpress-gutentor-plugin-password-disclosure-via-rest-api"},{"cve":"CVE-2026-74020","cvss":7.5,"epss":0.0039,"slug":"cve-2026-74020-koji-wordpress-theme-broken-access-control","title":"Koji WordPress Theme broken access control","severity":"high","exploited":false,"published_at":"2026-08-20T12:16:37.69+00:00","url":"https://junglewise.ai/threats/cve-2026-74020-koji-wordpress-theme-broken-access-control"},{"cve":"CVE-2026-66594","cvss":8.5,"epss":0.0036,"slug":"cve-2026-66594-wordpress-persistent-login-sql-injection-in-subscriber-role","title":"WordPress Persistent Login SQL injection in subscriber role","severity":"high","exploited":false,"published_at":"2026-08-20T12:16:33.307+00:00","url":"https://junglewise.ai/threats/cve-2026-66594-wordpress-persistent-login-sql-injection-in-subscriber-role"},{"cve":"CVE-2026-19615","cvss":6.8,"epss":0.0043,"slug":"cve-2026-19615-wordpress-admin-and-site-enhancements-stored-xss-via-svg-upload","title":"WordPress Admin and Site Enhancements stored XSS via SVG upload","severity":"medium","exploited":false,"published_at":"2026-08-20T06:17:07.777+00:00","url":"https://junglewise.ai/threats/cve-2026-19615-wordpress-admin-and-site-enhancements-stored-xss-via-svg-upload"},{"cve":"CVE-2026-15939","cvss":2.7,"epss":0.003,"slug":"cve-2026-15939-simple-restrict-authorization-bypass-in-rest-api","title":"Simple Restrict authorization bypass in REST API","severity":"low","exploited":false,"published_at":"2026-08-02T06:16:37.98+00:00","url":"https://junglewise.ai/threats/cve-2026-15939-simple-restrict-authorization-bypass-in-rest-api"}],"vendor":{"hub":true,"name":"WordPress.org","slug":"wordpress-org","url":"https://junglewise.ai/threats/vendors/wordpress-org"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"most_severe":[{"cve":"CVE-2026-16502","cvss":8.8,"epss":0.0045,"slug":"cve-2026-16502-live-composer-php-object-injection-via-deserialization","title":"Live Composer PHP Object Injection via deserialization","severity":"high","exploited":false,"published_at":"2026-09-08T12:16:52.443+00:00","url":"https://junglewise.ai/threats/cve-2026-16502-live-composer-php-object-injection-via-deserialization"},{"cve":"CVE-2026-86583","cvss":8.8,"epss":0.0033,"slug":"cve-2026-86583-the-import-and-export-users-and-customers-plugin-for-wordpress-is","title":"Import and export users and customers plugin privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-23T22:16:59.22+00:00","url":"https://junglewise.ai/threats/cve-2026-86583-the-import-and-export-users-and-customers-plugin-for-wordpress-is"},{"cve":"CVE-2026-66594","cvss":8.5,"epss":0.0036,"slug":"cve-2026-66594-wordpress-persistent-login-sql-injection-in-subscriber-role","title":"WordPress Persistent Login SQL injection in subscriber role","severity":"high","exploited":false,"published_at":"2026-08-20T12:16:33.307+00:00","url":"https://junglewise.ai/threats/cve-2026-66594-wordpress-persistent-login-sql-injection-in-subscriber-role"},{"cve":"CVE-2026-74020","cvss":7.5,"epss":0.0039,"slug":"cve-2026-74020-koji-wordpress-theme-broken-access-control","title":"Koji WordPress Theme broken access control","severity":"high","exploited":false,"published_at":"2026-08-20T12:16:37.69+00:00","url":"https://junglewise.ai/threats/cve-2026-74020-koji-wordpress-theme-broken-access-control"},{"cve":"CVE-2026-93778","cvss":7.2,"epss":0.0043,"slug":"cve-2026-93778-the-wp-yelp-review-slider-plugin-for-wordpress-is-vulnerable-to","title":"WP Yelp Review Slider stored cross-site scripting in review text","severity":"high","exploited":false,"published_at":"2026-09-22T08:16:42.767+00:00","url":"https://junglewise.ai/threats/cve-2026-93778-the-wp-yelp-review-slider-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-96752","cvss":7.2,"epss":0.0024,"slug":"cve-2026-96752-the-zero-spam-for-wordpress-plugin-for-wordpress-is-vulnerable-to","title":"Zero Spam for WordPress stored XSS in Contact Form 7","severity":"high","exploited":false,"published_at":"2026-09-25T08:16:42.7+00:00","url":"https://junglewise.ai/threats/cve-2026-96752-the-zero-spam-for-wordpress-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-94573","cvss":7.2,"epss":0.0024,"slug":"cve-2026-94573-the-repeater-fields-for-elementor-forms-plugin-for-wordpress-is","title":"Repeater Fields for Elementor Forms stored cross-site scripting","severity":"high","exploited":false,"published_at":"2026-09-25T08:16:42.047+00:00","url":"https://junglewise.ai/threats/cve-2026-94573-the-repeater-fields-for-elementor-forms-plugin-for-wordpress-is"},{"cve":"CVE-2026-19615","cvss":6.8,"epss":0.0043,"slug":"cve-2026-19615-wordpress-admin-and-site-enhancements-stored-xss-via-svg-upload","title":"WordPress Admin and Site Enhancements stored XSS via SVG upload","severity":"medium","exploited":false,"published_at":"2026-08-20T06:17:07.777+00:00","url":"https://junglewise.ai/threats/cve-2026-19615-wordpress-admin-and-site-enhancements-stored-xss-via-svg-upload"},{"cve":"CVE-2026-11996","cvss":6.4,"epss":0.0021,"slug":"cve-2026-11996-wordpress-advanced-popups-plugin-stored-cross-site-scripting","title":"WordPress Advanced Popups plugin stored cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-16T04:17:53.683+00:00","url":"https://junglewise.ai/threats/cve-2026-11996-wordpress-advanced-popups-plugin-stored-cross-site-scripting"},{"cve":"CVE-2026-96766","cvss":6.4,"epss":0.002,"slug":"cve-2026-96766-the-geodirectory-wp-business-directory-plugin-and-classified","title":"GeoDirectory stored cross-site scripting in business_hours parameter","severity":"medium","exploited":false,"published_at":"2026-09-25T07:16:57.017+00:00","url":"https://junglewise.ai/threats/cve-2026-96766-the-geodirectory-wp-business-directory-plugin-and-classified"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[]}