📦

wordpress

Vendor: wordpress

Actively Exploited 3 CISA KEV List
PoC / Exploits 172 Code Available
Total RCEs 42 Remote Access
Total CVEs 3285 Total Indexed
Avg. EPSS 6.70% Exploit Prob.
Latest CVE CVE-2026-63030 Jul 17

Security Vulnerability Index

Page 4 / 329
6.1 CVSS

WordPress before 5.5.2 allows stored XSS via post slugs.

EPSS: 2.61%
9.8 CVSS

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

EPSS: 7.47%
9.8 CVSS

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

EPSS: 4.84%
9.8 CVSS

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

EPSS: 4.14%
6.1 CVSS

WordPress before 5.5.2 allows XSS associated with global variables.

EPSS: 1.70%
7.5 CVSS

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

EPSS: 2.58%
9.8 CVSS
CVE-2020-28032
RCE Exploit Found

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

EPSS: 15.58%
8.8 CVSS

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

EPSS: 5.70%
5.3 CVSS

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

EPSS: 1.93%
3.5 CVSS

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

EPSS: 1.69%