Feed live

WordPress vulnerabilities - every known CVE across core, plugins, and themes

WordPress's attack surface comes mostly from its plugin and theme ecosystem, not core itself. Every disclosed CVE is scored, classified, and cross-referenced against the components that caused it.

Total CVEs tracked
352,137
All time
Critical · Active
12,432
CVSS ≥ 9.0
New · 14 days
2,112
Newly disclosed
Feed last synced
1 hr ago
Data freshness

WordPress security

The most targeted web platform

WordPress powers over 40% of all websites, which makes it the most targeted platform on the web. WordPress core is actively maintained and gets automatic security updates for minor releases. Core itself has relatively few CVEs each year. The real risk is in plugins and themes. There are over 60,000 plugins in the official directory, built by many different developers with varying security practices. One vulnerable plugin installed across millions of sites can be actively exploited within hours of a CVE going public.

The most common vulnerability types in the WordPress ecosystem are cross-site scripting (XSS), SQL injection, broken access control, cross-site request forgery (CSRF), PHP object injection, and unrestricted file upload. XSS and access control failures account for most WordPress CVEs. They are usually found in plugin code that processes user input without proper sanitisation or permission checks.

This database tracks every CVE that affects WordPress core, plugins, themes, and page builders including Elementor, Divi, WPBakery, and Beaver Builder. Records come from the official NVD feed and are updated continuously.

Triage and remediation

From CVE to fix

Search by plugin name, theme name, or vendor to filter the list down to what you care about. Click any CVE ID to open the full record: CVSS score breakdown, affected version range, disclosure dates, and a link to the original NVD entry.

If a plugin or theme on one of your sites shows up here with a Critical or High rating and your installed version is within the affected range, update or remove it right away. Most WordPress plugin vulnerabilities are patched within days of CVE assignment. Check the plugin changelog for a security release newer than the affected range. If the plugin has been abandoned or removed from WordPress.org, removal is the only safe option.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact
Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-87917 medium 6.1/10 Sep 19, 2026 yesterday
CVE-2026-16482 high 7.5/10 Sep 12, 2026 8d ago
CVE-2026-77705 Sep 12, 2026 8d ago
CVE-2026-81789 high 8.6/10 Sep 10, 2026 9d ago
CVE-2026-85305 medium 5.4/10 Sep 3, 2026 16d ago
CVE-2026-84847 high 7.5/10 Sep 3, 2026 16d ago
CVE-2026-84812 high 7.1/10 Sep 3, 2026 16d ago
CVE-2026-84774 medium 6.1/10 Sep 3, 2026 16d ago
CVE-2026-84766 medium 5.9/10 Sep 3, 2026 16d ago
CVE-2026-84758 medium 6.5/10 Sep 3, 2026 16d ago
CVE-2026-84753 critical 9.8/10 Sep 3, 2026 16d ago
CVE-2026-84215 medium 6.5/10 Sep 3, 2026 16d ago
CVE-2026-81773 high 7.1/10 Sep 3, 2026 16d ago
CVE-2026-81292 high 7.1/10 Sep 3, 2026 16d ago
CVE-2026-84849 medium 6.5/10 Sep 3, 2026 16d ago
CVE-2026-84815 medium 5.8/10 Sep 3, 2026 16d ago
CVE-2026-84217 medium 5.4/10 Sep 2, 2026 17d ago
CVE-2026-84835 medium 5.3/10 Sep 2, 2026 17d ago
CVE-2026-66652 medium 5.4/10 Sep 2, 2026 17d ago
CVE-2026-81772 high 8.8/10 Sep 2, 2026 17d ago
CVE-2026-84781 medium 6.5/10 Sep 2, 2026 17d ago
CVE-2026-82883 high 7.1/10 Sep 2, 2026 18d ago
CVE-2026-18550 critical 9.8/10 Sep 1, 2026 18d ago
CVE-2026-82226 critical 9.8/10 Aug 31, 2026 19d ago
CVE-2026-81778 medium 6.5/10 Aug 31, 2026 19d ago
CVE-2026-81762 medium 6.5/10 Aug 31, 2026 19d ago
CVE-2026-81296 high 7.5/10 Aug 31, 2026 19d ago
CVE-2026-81280 medium 6.5/10 Aug 31, 2026 19d ago
CVE-2026-83492 medium 6.9/10 Aug 31, 2026 19d ago
CVE-2026-74010 medium 5.3/10 Aug 31, 2026 19d ago
Page 1
Prev 1 2