{"schema_version":1,"title":"Wordpress vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 122 vulnerabilities in Wordpress: 9 in the last 7 days and 59 in the last 90 days, 16 of them critical and 6 exploited in the wild. The most recent, CVE-2026-85081, was published on 26 September 2026. 5 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/wordpress","json_url":"https://junglewise.ai/threats/vendors/wordpress.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/wordpress","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":39,"all_time":122,"critical":16,"exploited":6,"last_7_days":9,"last_30_days":36,"last_90_days":59,"last_365_days":105},"latest":[{"cve":"CVE-2026-85081","slug":"cve-2026-85081-the-file-manager-wordpress-plugin-before-8-0-5-fileorganizer","title":"WordPress File Manager plugins DOM-based XSS via postMessage origin bypass","severity":"info","exploited":false,"published_at":"2026-09-26T07:17:02.823+00:00","url":"https://junglewise.ai/threats/cve-2026-85081-the-file-manager-wordpress-plugin-before-8-0-5-fileorganizer"},{"cve":"CVE-2025-14814","cvss":6.4,"epss":0.0016,"slug":"cve-2025-14814-the-css-javascript-toolbox-plugin-for-wordpress-is-vulnerable-to","title":"CSS & JavaScript Toolbox plugin stored cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-25T04:17:31.093+00:00","url":"https://junglewise.ai/threats/cve-2025-14814-the-css-javascript-toolbox-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-88843","cvss":7.2,"epss":0.0036,"slug":"cve-2026-88843-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS path traversal in Elementor widget","severity":"high","exploited":false,"published_at":"2026-09-24T06:17:03.207+00:00","url":"https://junglewise.ai/threats/cve-2026-88843-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-95528","cvss":7.1,"epss":0.0018,"slug":"cve-2026-95528-unauthenticated-cross-site-scripting-xss-in-core-web-vitals","title":"Core Web Vitals & PageSpeed Booster XSS","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:52.107+00:00","url":"https://junglewise.ai/threats/cve-2026-95528-unauthenticated-cross-site-scripting-xss-in-core-web-vitals"},{"cve":"CVE-2026-93774","cvss":7.1,"epss":0.0019,"slug":"cve-2026-93774-unauthenticated-cross-site-scripting-xss-in-wp-photo-album-plus-9","title":"WP Photo Album Plus unauthenticated cross-site scripting","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:46.753+00:00","url":"https://junglewise.ai/threats/cve-2026-93774-unauthenticated-cross-site-scripting-xss-in-wp-photo-album-plus-9"},{"cve":"CVE-2026-89331","cvss":5.3,"epss":0.0021,"slug":"cve-2026-89331-the-fluentboards-wordpress-plugin-before-2-1-0-does-not-properly","title":"WordPress FluentBoards information disclosure in public board","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:05.083+00:00","url":"https://junglewise.ai/threats/cve-2026-89331-the-fluentboards-wordpress-plugin-before-2-1-0-does-not-properly"},{"cve":"CVE-2026-86783","cvss":5.3,"epss":0.0021,"slug":"cve-2026-86783-the-post-grid-gutenberg-blocks-wordpress-plugin-before-5-0-41","title":"Post Grid Gutenberg Blocks REST API information disclosure","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:04.13+00:00","url":"https://junglewise.ai/threats/cve-2026-86783-the-post-grid-gutenberg-blocks-wordpress-plugin-before-5-0-41"},{"cve":"CVE-2026-87902","cvss":8.1,"epss":0.0288,"slug":"cve-2026-87902-wordpress-core-remote-file-inclusion","title":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the","severity":"critical","exploited":true,"published_at":"2026-09-22T17:17:28.31+00:00","url":"https://junglewise.ai/threats/cve-2026-87902-wordpress-core-remote-file-inclusion"},{"cve":"CVE-2026-92410","cvss":4.3,"epss":0.0014,"slug":"cve-2026-92410-the-sign-up-sheets-wordpress-plugin-before-2-4-0-does-not","title":"Sign-up Sheets WordPress plugin CSRF in sign-up deletion","severity":"medium","exploited":false,"published_at":"2026-09-20T07:16:50.957+00:00","url":"https://junglewise.ai/threats/cve-2026-92410-the-sign-up-sheets-wordpress-plugin-before-2-4-0-does-not"},{"cve":"CVE-2026-9232","cvss":6.5,"epss":0.0048,"slug":"cve-2026-9232-the-easy-appointments-plugin-for-wordpress-is-vulnerable-to","title":"Easy Appointments sensitive information exposure","severity":"medium","exploited":false,"published_at":"2026-09-19T08:16:55.053+00:00","url":"https://junglewise.ai/threats/cve-2026-9232-the-easy-appointments-plugin-for-wordpress-is-vulnerable-to"},{"cve":"CVE-2026-89093","cvss":5.3,"epss":0.0056,"slug":"cve-2026-89093-the-better-messages-chat-rooms-group-chat-private-messages-ai","title":"Better Messages , Chat Rooms spoofing by IP header forgery","severity":"medium","exploited":false,"published_at":"2026-09-19T03:17:16.443+00:00","url":"https://junglewise.ai/threats/cve-2026-89093-the-better-messages-chat-rooms-group-chat-private-messages-ai"},{"cve":"CVE-2026-89138","cvss":4.3,"epss":0.0039,"slug":"cve-2026-89138-wordpress-filter-gallery-authorization-bypass","title":"WordPress Filter Gallery authorization bypass","severity":"medium","exploited":false,"published_at":"2026-09-18T07:16:50.907+00:00","url":"https://junglewise.ai/threats/cve-2026-89138-wordpress-filter-gallery-authorization-bypass"},{"cve":"CVE-2026-12106","cvss":6.4,"epss":0.0025,"slug":"cve-2026-12106-wordpress-auto-upload-images-limited-server-side-request-forgery","title":"WordPress Auto Upload Images limited server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-18T07:16:49.457+00:00","url":"https://junglewise.ai/threats/cve-2026-12106-wordpress-auto-upload-images-limited-server-side-request-forgery"},{"cve":"CVE-2026-90978","cvss":7.1,"epss":0.0034,"slug":"cve-2026-90978-wordpress-filter-gallery-nonce-verification-bypass-in-ajax","title":"WordPress Filter Gallery nonce verification bypass in AJAX handlers","severity":"high","exploited":false,"published_at":"2026-09-18T06:16:41.73+00:00","url":"https://junglewise.ai/threats/cve-2026-90978-wordpress-filter-gallery-nonce-verification-bypass-in-ajax"},{"cve":"CVE-2026-88993","cvss":6.8,"epss":0.0043,"slug":"cve-2026-88993-all-bootstrap-blocks-stored-xss-in-block-attribute","title":"All Bootstrap Blocks stored XSS in block attribute","severity":"medium","exploited":false,"published_at":"2026-09-18T06:16:41.373+00:00","url":"https://junglewise.ai/threats/cve-2026-88993-all-bootstrap-blocks-stored-xss-in-block-attribute"},{"cve":"CVE-2026-87771","cvss":8.6,"epss":0.0045,"slug":"cve-2026-87771-product-question-and-answer-sql-injection","title":"Product Question and Answer SQL injection","severity":"high","exploited":false,"published_at":"2026-09-18T06:16:40.523+00:00","url":"https://junglewise.ai/threats/cve-2026-87771-product-question-and-answer-sql-injection"},{"cve":"CVE-2026-16750","cvss":5.3,"epss":0.0024,"slug":"cve-2026-16750-the-motors-car-dealership-and-classified-listings-plugin","title":"The Motors Car Dealership and Classified Listings Plugin authorization bypass","severity":"medium","exploited":false,"published_at":"2026-09-17T22:16:59.143+00:00","url":"https://junglewise.ai/threats/cve-2026-16750-the-motors-car-dealership-and-classified-listings-plugin"},{"cve":"CVE-2026-16582","cvss":5.3,"epss":0.0023,"slug":"cve-2026-16582-booking-for-appointments-and-events-calendar-amelia-authorization","title":"Booking for Appointments and Events Calendar , Amelia authorization bypass in payment validation","severity":"medium","exploited":false,"published_at":"2026-09-17T22:16:58.997+00:00","url":"https://junglewise.ai/threats/cve-2026-16582-booking-for-appointments-and-events-calendar-amelia-authorization"},{"cve":"CVE-2026-86801","cvss":8.8,"epss":0.0051,"slug":"cve-2026-86801-wordpress-to-do-list-member-plugin-unauthenticated-file-upload","title":"WordPress To Do List Member plugin unauthenticated file upload and XSS","severity":"high","exploited":false,"published_at":"2026-09-17T07:16:28.413+00:00","url":"https://junglewise.ai/threats/cve-2026-86801-wordpress-to-do-list-member-plugin-unauthenticated-file-upload"},{"cve":"CVE-2026-87935","cvss":8.1,"epss":0.0091,"slug":"cve-2026-87935-wordpress-paid-downloads-arbitrary-file-upload","title":"WordPress Paid Downloads arbitrary file upload","severity":"high","exploited":false,"published_at":"2026-09-17T05:17:02.263+00:00","url":"https://junglewise.ai/threats/cve-2026-87935-wordpress-paid-downloads-arbitrary-file-upload"},{"cve":"CVE-2026-85681","cvss":9.8,"epss":0.005,"slug":"cve-2026-85681-wp-component-wordpress-plugin-unauthenticated-privilege","title":"WP Component WordPress plugin unauthenticated privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-12T06:16:27.25+00:00","url":"https://junglewise.ai/threats/cve-2026-85681-wp-component-wordpress-plugin-unauthenticated-privilege"},{"cve":"CVE-2026-14563","cvss":9.8,"epss":0.0028,"slug":"cve-2026-14563-wordpress-advanced-customized-prompts-authentication-bypass","title":"WordPress Advanced Customized Prompts authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-11T07:16:46.177+00:00","url":"https://junglewise.ai/threats/cve-2026-14563-wordpress-advanced-customized-prompts-authentication-bypass"},{"cve":"CVE-2026-14560","cvss":10,"epss":0.0044,"slug":"cve-2026-14560-wordpress-teddy-bear-customize-addon-arbitrary-file-upload","title":"WordPress Teddy Bear Customize Addon arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-11T07:16:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-14560-wordpress-teddy-bear-customize-addon-arbitrary-file-upload"},{"cve":"CVE-2026-81754","cvss":7.2,"epss":0.0042,"slug":"cve-2026-81754-wordpress-the-vigilant-plugin-stored-xss-via-user-agent-header","title":"WordPress The Vigilant plugin stored XSS via User-Agent header","severity":"high","exploited":false,"published_at":"2026-09-11T04:17:58.19+00:00","url":"https://junglewise.ai/threats/cve-2026-81754-wordpress-the-vigilant-plugin-stored-xss-via-user-agent-header"},{"cve":"CVE-2026-18964","cvss":6.1,"epss":0.0022,"slug":"cve-2026-18964-wordpress-chaty-plugin-reflected-xss-via-search-parameter","title":"WordPress Chaty plugin reflected XSS via search parameter","severity":"medium","exploited":false,"published_at":"2026-09-11T04:17:24.76+00:00","url":"https://junglewise.ai/threats/cve-2026-18964-wordpress-chaty-plugin-reflected-xss-via-search-parameter"}],"vendor":{"hub":true,"name":"Wordpress","slug":"wordpress","homepage":"https://wordpress.org/","description":"WordPress is an open-source content management system based on PHP and MySQL.","url":"https://junglewise.ai/threats/vendors/wordpress"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":2,"exploited":2,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":1,"exploited":0,"vulnerabilities":6},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":7},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":2,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":4,"exploited":0,"vulnerabilities":12},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-09-21","critical":1,"exploited":1,"vulnerabilities":8}],"most_severe":[{"cve":"CVE-2020-25213","cvss":9.8,"slug":"cve-2020-25213-wordpress-file-manager-plugin-remote-code-execution-vulnerability","title":"WordPress File Manager Plugin Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-25213-wordpress-file-manager-plugin-remote-code-execution-vulnerability"},{"cve":"CVE-2026-60137","cvss":9.1,"epss":0.0403,"slug":"cve-2026-60137-wordpress-sql-injection-in-wp-query-author-not-in-parameter","title":"WordPress SQL injection in WP_Query author__not_in parameter","severity":"critical","exploited":true,"published_at":"2026-07-17T20:17:27.79+00:00","url":"https://junglewise.ai/threats/cve-2026-60137-wordpress-sql-injection-in-wp-query-author-not-in-parameter"},{"cve":"CVE-2026-87902","cvss":8.1,"epss":0.0288,"slug":"cve-2026-87902-wordpress-core-remote-file-inclusion","title":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the","severity":"critical","exploited":true,"published_at":"2026-09-22T17:17:28.31+00:00","url":"https://junglewise.ai/threats/cve-2026-87902-wordpress-core-remote-file-inclusion"},{"cve":"CVE-2026-63030","cvss":7.5,"epss":0.0895,"slug":"cve-2026-63030-wordpress-rest-api-route-confusion-and-sql-injection-leading-to","title":"WordPress REST API route confusion and SQL injection leading to RCE","severity":"critical","exploited":true,"published_at":"2026-07-17T20:17:28.49+00:00","url":"https://junglewise.ai/threats/cve-2026-63030-wordpress-rest-api-route-confusion-and-sql-injection-leading-to"},{"cve":"CVE-2020-11738","cvss":7.5,"slug":"cve-2020-11738-wordpress-snap-creek-duplicator-plugin-file-download","title":"WordPress Snap Creek Duplicator Plugin File Download Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-11738-wordpress-snap-creek-duplicator-plugin-file-download"},{"cve":"CVE-2019-9978","cvss":6.1,"slug":"cve-2019-9978-wordpress-social-warfare-plugin-cross-site-scripting-xss","title":"WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-9978-wordpress-social-warfare-plugin-cross-site-scripting-xss"},{"cve":"CVE-2026-4357","cvss":10,"epss":0.0055,"slug":"cve-2026-4357-wordpress-embed-html5-game-plugin-unauthenticated-file-upload","title":"WordPress Embed HTML5 Game plugin unauthenticated file upload","severity":"critical","exploited":false,"published_at":"2026-09-02T15:17:38.413+00:00","url":"https://junglewise.ai/threats/cve-2026-4357-wordpress-embed-html5-game-plugin-unauthenticated-file-upload"},{"cve":"CVE-2026-14560","cvss":10,"epss":0.0044,"slug":"cve-2026-14560-wordpress-teddy-bear-customize-addon-arbitrary-file-upload","title":"WordPress Teddy Bear Customize Addon arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-11T07:16:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-14560-wordpress-teddy-bear-customize-addon-arbitrary-file-upload"},{"cve":"CVE-2026-85681","cvss":9.8,"epss":0.005,"slug":"cve-2026-85681-wp-component-wordpress-plugin-unauthenticated-privilege","title":"WP Component WordPress plugin unauthenticated privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-12T06:16:27.25+00:00","url":"https://junglewise.ai/threats/cve-2026-85681-wp-component-wordpress-plugin-unauthenticated-privilege"},{"cve":"CVE-2025-15689","cvss":9.8,"epss":0.0048,"slug":"cve-2025-15689-wordpress-capella-theme-privilege-escalation","title":"WordPress Capella Theme privilege escalation","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:31.89+00:00","url":"https://junglewise.ai/threats/cve-2025-15689-wordpress-capella-theme-privilege-escalation"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Wordpress","slug":"wordpress","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/wordpress"},{"name":"Wordpress Advanced Customized Prompts","slug":"advanced-customized-prompts","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/advanced-customized-prompts"},{"name":"Wordpress Filter Gallery","slug":"filter-gallery","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/filter-gallery"},{"name":"Wordpress Login & Register Forms","slug":"login-register-forms","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/login-register-forms"},{"name":"Wordpress User Access Manager","slug":"user-access-manager","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/user-access-manager"}]}