Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress CRITICAL 9.8
CVE-2026-63030 KEVEPSS 96%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

Fix: 6.9.5 / 7.0.2+
Fix from $2,300 2026-07-17
WordPress MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

Fix: 6.8.6 / 6.9.5+
Fix from $1,600 2026-07-17
WordPress MEDIUM 5.4
CVE-2022-4973

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the…

Fix: after 6.0.2
Fix from $1,600 2024-10-16
Thanh Toan Quet Ma Qr Code Tu Dong HIGH 7.2
CVE-2024-8914

The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Fix: after 2.0.1
Fix from $1,950 2024-09-25
WordPress MEDIUM 6.1
CVE-2024-4439EPSS 71%

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insuffi…

Fix: after 6.5.1
Fix from $1,600 2024-05-03
WordPress CRITICAL 9.8
CVE-2024-31211

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__…

Fix: 6.4.2+
Fix from $2,300 2024-04-04
WordPress HIGH 8.8
CVE-2024-31210

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an …

Fix: 4.1.40 / 4.2.37+
Fix from $1,950 2024-04-04
WordPress MEDIUM 5.3
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addre…

Fix: 4.7.27 / 4.8.23+
Fix from $1,600 2023-10-16
WordPress MEDIUM 5.4
CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.…

Fix: after 16.8.0
Fix from $1,600 2023-10-13
Blogger Importer HIGH 8.8
CVE-2013-10027

A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/re…

Fix: 0.6+
Fix from $1,950 2023-06-04
Performance Lab HIGH 8.8
CVE-2022-47174

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.

Fix: after 2.2.0
Fix from $1,950 2023-05-25
Health Check \& Troubleshooting HIGH 8.8
CVE-2022-47161

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

Fix: after 1.5.1
Fix from $1,950 2023-05-25
WordPress MEDIUM 5.4
CVE-2023-2745EPSS 80%

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated a…

Fix: 4.1.38 / 4.2.35+
Fix from $1,600 2023-05-17
Debug Bar MEDIUM 6.1
CVE-2013-10021

A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the…

Fix: 0.8.1+
Fix from $1,600 2023-03-11
WordPress MEDIUM 5.3
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code…

Fix: after 6.1.1
Fix from $1,600 2023-01-05
WordPress MEDIUM 5.9
CVE-2022-3590

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and …

Fix: after 6.1.1
Fix from $1,600 2022-12-14
WordPress MEDIUM 6.1
CVE-2022-43497

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d…

Fix: 3.7.40 / 3.8.40+
Fix from $1,600 2022-12-05
WordPress MEDIUM 6.1
CVE-2022-43500

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d…

Fix: 3.7.40 / 3.8.40+
Fix from $1,600 2022-12-05
WordPress MEDIUM 5.3
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th…

Fix: 3.7.40 / 3.8.40+
Fix from $1,600 2022-12-05
WordPress MEDIUM 6.5
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow…

Fix: 3.0.6 / 3.1.2+
Fix from $1,600 2022-04-18
WordPress HIGH 8.8
CVE-2022-21664

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization i…

Fix: 5.8.3+
Fix from $1,950 2022-01-06
WordPress HIGH 7.2
CVE-2022-21663

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…

Fix: 5.8.3+
Fix from $1,950 2022-01-06
WordPress MEDIUM 5.4
CVE-2022-21662EPSS 65%

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (…

Fix: 5.8.3+
Fix from $1,600 2022-01-06
WordPress HIGH 7.5
CVE-2022-21661EPSS 98%

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Q…

Fix: 3.7.37 / 3.8.37+
Fix from $1,950 2022-01-06
WordPress CRITICAL 9.8
CVE-2021-44223EPSS 29%

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply…

Fix: 5.8+
Fix from $2,300 2021-11-25
WordPress MEDIUM 6.5
CVE-2021-39203

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen…

Mitigation only
Fix from $1,600 2021-09-09
WordPress MEDIUM 5.4
CVE-2021-39201

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows…

Fix: 5.8+
Fix from $1,600 2021-09-09
WordPress MEDIUM 5.4
CVE-2021-39202

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi…

Mitigation only
Fix from $1,600 2021-09-09
WordPress MEDIUM 5.3
CVE-2021-39200

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output…

Fix: 5.8.1+
Fix from $1,600 2021-09-09
WordPress CRITICAL 9.8
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…

Fix: 3.7.36 / 3.8.36+
Fix from $2,300 2021-04-28