Feed live

WordPress vulnerabilities - every known CVE across core, plugins, and themes

WordPress's attack surface comes mostly from its plugin and theme ecosystem, not core itself. Every disclosed CVE is scored, classified, and cross-referenced against the components that caused it.

Total CVEs tracked
349,462
All time
Critical · Active
12,228
CVSS ≥ 9.0
New · 14 days
3,095
Newly disclosed
Feed last synced
2 hrs ago
Data freshness

WordPress security

The most targeted web platform

WordPress powers over 40% of all websites, which makes it the most targeted platform on the web. WordPress core is actively maintained and gets automatic security updates for minor releases. Core itself has relatively few CVEs each year. The real risk is in plugins and themes. There are over 60,000 plugins in the official directory, built by many different developers with varying security practices. One vulnerable plugin installed across millions of sites can be actively exploited within hours of a CVE going public.

The most common vulnerability types in the WordPress ecosystem are cross-site scripting (XSS), SQL injection, broken access control, cross-site request forgery (CSRF), PHP object injection, and unrestricted file upload. XSS and access control failures account for most WordPress CVEs. They are usually found in plugin code that processes user input without proper sanitisation or permission checks.

This database tracks every CVE that affects WordPress core, plugins, themes, and page builders including Elementor, Divi, WPBakery, and Beaver Builder. Records come from the official NVD feed and are updated continuously.

Triage and remediation

From CVE to fix

Search by plugin name, theme name, or vendor to filter the list down to what you care about. Click any CVE ID to open the full record: CVSS score breakdown, affected version range, disclosure dates, and a link to the original NVD entry.

If a plugin or theme on one of your sites shows up here with a Critical or High rating and your installed version is within the affected range, update or remove it right away. Most WordPress plugin vulnerabilities are patched within days of CVE assignment. Check the plugin changelog for a security release newer than the affected range. If the plugin has been abandoned or removed from WordPress.org, removal is the only safe option.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact
Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-82220 medium 5.3/10 Aug 28, 2026 2d ago
CVE-2026-81767 high 7.5/10 Aug 28, 2026 2d ago
CVE-2026-81761 medium 4.3/10 Aug 28, 2026 2d ago
CVE-2026-81760 high 7.1/10 Aug 28, 2026 2d ago
CVE-2026-81759 medium 5.4/10 Aug 28, 2026 2d ago
CVE-2026-81757 high 7.2/10 Aug 28, 2026 2d ago
CVE-2026-81299 medium 4.3/10 Aug 28, 2026 2d ago
CVE-2026-81285 high 7.5/10 Aug 28, 2026 2d ago
CVE-2026-82227 high 8.5/10 Aug 28, 2026 2d ago
CVE-2026-81284 medium 4.3/10 Aug 28, 2026 2d ago
CVE-2026-82222 critical 10.0/10 Aug 28, 2026 2d ago
CVE-2026-81777 medium 5.3/10 Aug 28, 2026 2d ago
CVE-2026-82123 medium 6.5/10 Aug 28, 2026 2d ago
CVE-2026-81277 high 8.5/10 Aug 27, 2026 3d ago
CVE-2026-81276 medium 5.3/10 Aug 27, 2026 3d ago
CVE-2026-81274 medium 5.3/10 Aug 27, 2026 3d ago
CVE-2026-81273 high 8.1/10 Aug 27, 2026 3d ago
CVE-2026-81272 medium 4.9/10 Aug 27, 2026 3d ago
CVE-2026-81271 high 8.8/10 Aug 27, 2026 3d ago
CVE-2026-80433 high 7.5/10 Aug 27, 2026 3d ago
CVE-2026-78293 high 7.1/10 Aug 27, 2026 3d ago
CVE-2026-78292 critical 9.8/10 Aug 27, 2026 3d ago
CVE-2026-78289 high 7.1/10 Aug 27, 2026 3d ago
CVE-2026-78288 critical 9.3/10 Aug 27, 2026 3d ago
CVE-2026-78286 critical 9.8/10 Aug 27, 2026 3d ago
CVE-2026-78285 high 8.5/10 Aug 27, 2026 3d ago
CVE-2026-78283 high 7.1/10 Aug 27, 2026 3d ago
CVE-2026-78281 high 7.1/10 Aug 27, 2026 3d ago
CVE-2026-78276 high 7.2/10 Aug 27, 2026 3d ago
CVE-2026-78275 medium 6.8/10 Aug 27, 2026 3d ago
Page 1
Prev 1 2