WordPress vulnerabilities
24 CVEs tracked
WordPress is prominent in recent reports due to critical core vulnerabilities alongside ongoing plugin-level issues. The key event is the addition of chained vulnerabilities CVE-2026-60137 (SQL Injection) and CVE-2026-63030 (Interpretation Conflict) to the KEV catalog, which together allow unauthenticated RCE on default installations. Other plugin flaws like CVE-2026-15648 (Stored XSS) continue to be reported. Defenders must prioritize immediate core updates, audit plugins for reported CVEs, and aggressively monitor Web Application Firewall (WAF) logs for SQL injection attempts.
Azərbaycanca: WordPress, həm əsas nüvəsi, həm də üçüncü tərəf plaginləri ilə bağlı kritik hesabatlarda önə çıxır. Əsas hadisə CVE-2026-60137 (SQL Injection) və CVE-2026-63030 (Interpretation Conflict) zəifliklərinin KEV siyahısına əlavə edilməsidir, bu iki zəiflik birlikdə standart WordPress qurğularında authsiz RCE-yə imkan verir. Paralel olaraq CVE-2026-15648 (Stored XSS) kimi plagin səviyyəli problemlər bildirilir. Müdafiəçilər əsas diqqəti WordPress nüvəsini təcili yeniləməyə, plagin auditinə və şübhəli SQL sorğularına qarşı Web Application Firewall (WAF) monitorinqinə yönəltməlidir.
This vendor's CVEs24
- CVE-2026-63030KEVEPSS 97%
- CVE-2026-60137KEVEPSS 78%
- CVE-2026-65640EPSS 2%
- CVE-2026-48094EPSS 0.30%
- CVE-2026-45293EPSS 0.18%
- CVE-2026-18855EPSS 1%
- CVE-2026-18072EPSS 0.88%
- CVE-2026-17023EPSS 0.17%
- CVE-2026-16993EPSS 0.17%
- CVE-2026-16605EPSS 0.32%
- CVE-2026-16282EPSS 0.18%
- CVE-2026-16094EPSS 0.35%
- CVE-2026-16080EPSS 0.24%
- CVE-2026-15648EPSS 0.19%
- CVE-2026-15239EPSS 0.11%
- CVE-2026-15236EPSS 0.28%
- CVE-2026-14833EPSS 0.23%
- CVE-2026-14270EPSS 0.53%
- CVE-2026-14182EPSS 0.30%
- CVE-2026-13329EPSS 0.17%
- CVE-2026-8761EPSS 0.36%
- CVE-2026-8457EPSS 0.44%
- CVE-2026-2916EPSS 0.22%
- CVE-2025-15675EPSS 0.17%
This hub is built from skopnix's own reporting on WordPress: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.