Pricing
Case studies
Login
Start trial
WordPress
N/A
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress WordPress
No VDP
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
1 present
307 patched
4 Mitigation rules
XML External Entity (XXE) vulnerability
<= 6.9.3
10/03/2026
Broken Access Control in Notes vulnerability
6.9-6.9.3
10/03/2026
Missing Authorization to Authenticated (Author+) Sensitive Information Disclosure vulnerability
<= 6.9.1
10/03/2026
Server-Side Request Forgery (SSRF) vulnerability
6.9-6.9.1
10/03/2026
Cross-Site Scripting vulnerability
6.9-6.9.1
10/03/2026
Stored Cross-Site Scripting
6.9-6.9.1
10/03/2026
(Author+) Cross Site Scripting (XSS) Vulnerability
<= 6.8.2
22/09/2025
(Contributor+) Sensitive Data Exposure Vulnerability
<= 6.8.2
22/09/2025
Contributor+ Path Traversal (Windows Only) vulnerability
< 6.5.5
25/06/2024
Cross Site Scripting (XSS) via template-part vulnerability
< 6.5.5
25/06/2024
Contributor+ Stored Cross-Site Scripting via HTML API
< 6.5.5
25/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting Via Avatar Block vulnerability
<= 6.5.0
09/04/2024
Sensitive Information Exposure via redirect_guess_404_permalink vulnerability
<= 6.4.3
05/04/2024
Auth. (Admin+) PHP File Upload vulnerability
< 6.4.3
31/01/2024
Cache Poisoning Denial of Service vulnerability
< 6.3.2
13/10/2023
Contributor+ Stored XSS in Navigation Links Block vulnerability
< 6.3.2
13/10/2023
Contributor+ Comment Read on Private and Password Protected Post vulnerability
< 6.3.2
13/10/2023
Reflected Cross-Site Scripting via Application Password Requests
< 6.3.2
13/10/2023
Sensitive Information Exposure via User Search REST Endpoint
< 6.3.2
13/10/2023
Auth. (Contributor+) Cross-Site Scripting via Footnotes Block
6.3-6.3.1
13/10/2023
Auth. (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode
< 6.3.2
13/10/2023
Unauth. Shortcode Execution vulnerability
<= 6.2.1
22/05/2023
Insufficient Sanitization of Block Attributes vulnerabilities
<= 6.2
17/05/2023
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 6.2
17/05/2023
Unauth. Shortcode Execution vulnerability
<= 6.2
17/05/2023
Unauth. Directory Traversal vulnerability
<= 6.2
17/05/2023
Cross-Site Request Forgery vulnerability
<= 6.2
17/05/2023
Unauthenticated Blind Server-Side Request Forgery vulnerability
<= 6.6.2
13/12/2022
Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
SQL Injection (SQLi) vulnerability
<= 6.0.2
18/10/2022
Content From Multipart Emails Leak vulnerability
<= 6.0.2
18/10/2022
Cross-Site Request Forgery (CSRF) vulnerability in wp-trackback.php
<= 6.0.2
18/10/2022
Stored Cross-Site Scripting (XSS) vulnerability in Comment editing
<= 6.0.2
18/10/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Reflected Cross-Site Scripting (XSS) via SQLi vulnerability
<= 6.0.2
18/10/2022
Sender’s Email Address Exposure vulnerability
<= 6.0.2
18/10/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 6.0.2
18/10/2022
Data Exposure vulnerability via REST API
<= 6.0.2
18/10/2022
Open redirect vulnerability
<= 6.0.2
18/10/2022
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 6.0.1
31/08/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 6.0.1
31/08/2022
Authenticated SQL Injection (SQLi) vulnerability via Link API
<= 6.0.1
31/08/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 5.9.1
11/03/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 5.8.2
06/01/2022
SQL Injection (SQLi) vulnerability
<= 5.8.2
06/01/2022
SQL Injection (SQLi) vulnerability
<= 5.8.2
06/01/2022
Authenticated Object Injection in Multisites
<= 5.8.2
06/01/2022
Plugin Confusion vulnerability
< 5.8
25/11/2021
Expired DST Root CA X3 Certificate issue
<= 5.8.1
10/11/2021
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 5.8
09/09/2021
Data Exposure via REST API vulnerability
<= 5.8
09/09/2021
Command injection vulnerability in the Lodash library
<= 5.8
09/09/2021
Object injection in PHPMailer vulnerability
<= 5.7.1
13/05/2021
XML External Entity (XXE) vulnerability
4.7-5.7
15/04/2021
Sensitive Data Exposure vulnerability
4.7-5.7
15/04/2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 5.5.1
29/10/2020
Bypass Protected Meta That Could Lead To Arbitrary File Deletion vulnerability
<= 5.5.1
29/10/2020
Stored Cross-Site Scripting (XSS) in Post Slugs vulnerability
<= 5.5.1
29/10/2020
Unauthenticated Denial-of-Service (DoS) Attack to Remote Code Execution (RCE) vulnerability
<= 5.5.1
29/10/2020
XML-RPC Privilege Escalation vulnerability
<= 5.5.1
29/10/2020
Cross-Site Scripting (XSS) via Global Variables vulnerability
<= 5.5.1
29/10/2020
Mishandling Embeds From Disabled Sites On a Multisite Network vulnerability
<= 5.5.1
29/10/2020
Mishandled deserialization requests vulnerability
<= 5.5.1
29/10/2020
wp_kses_bad_protocol() Colon Bypass vulnerability
<= 5.3
06/01/2020
Stored Cross-Site Scripting (XSS) vulnerability
<= 5.3
13/12/2019
Multiple security issues (XSS, SSRF, Cache Poisoning)
<= 5.2.3
15/10/2019
Cross-Site Scripting (XSS) vulnerability
<= 5.2.2
05/09/2019
Cross-Site Scripting (XSS) vulnerability
3.9-5.1
13/03/2019
Authenticated Code Execution vulnerability
3.7-5.0
28/02/2019
Authenticated File Delete vulnerability
<= 5.0
13/12/2018
Authenticated Post Type Bypass vulnerability
<= 5.0
13/12/2018
PHP Object Injection via Meta Data vulnerability
<= 5.0
13/12/2018
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 5.0
13/12/2018
Cross-Site Scripting (XSS) vulnerability that could affect plugins
<= 5.0
13/12/2018
User Activation Screen Search Engine Indexing
<= 5.0
13/12/2018
File Upload to XSS on Apache Web Servers vulnerability
<= 5.0
13/12/2018
Arbitrary Code Execution vulnerability
<= 4.9.6
27/06/2018
Security Misconfiguration with URL Hostnames
<= 4.9.4
05/04/2018
Use Safe Redirect for Login
<= 4.9.4
05/04/2018
Stored XSS in Generator Tag
<= 4.9.4
05/04/2018
Application Denial of Service (DoS) vulnerability
<= 4.9.2
05/02/2018
Cross-Site Scripting vulnerability
<= 4.9.1
17/01/2018
Authenticated JavaScript File Upload vulnerability
<= 4.9
01/12/2017
RSS and Atom Feed Escaping
<= 4.9
29/11/2017
HTML Language Attribute Escaping
<= 4.9
29/11/2017
newbloguser Key Bypass
<= 4.9
29/11/2017
potential SQL injection (SQLi), $wpdb->prepare() issue, possible unsafe queries
<= 4.8.2
31/10/2017
SQL injection (SQLi) vulnerability
<= 4.8.1
19/09/2017
Cross-Site Scripting (XSS) vulnerability (oEmbed)
<= 4.8.1
19/09/2017
Cross-Site Scripting (XSS) vulnerability (visual editor)
<= 4.8.1
19/09/2017
Cross-Site Scripting (XSS) vulnerability (plugin editor)
<= 4.8.1
19/09/2017
Cross-Site Scripting (XSS) vulnerability (template names)
<= 4.8.1
19/09/2017
Cross-Site Scripting (XSS) vulnerability (link modal)
<= 4.8.1
19/09/2017
Path traversal vulnerability (file unzipping code)
<= 4.8.1
19/09/2017
Path traversal vulnerability (customizer)
<= 4.8.1
19/09/2017
Open redirect vulnerability (user and term edit screens)
<= 4.8.1
19/09/2017
Insufficient Redirect Validation vulnerability
<= 4.7.4
17/05/2017
Post Meta Data Values Improper Handling in XML-RPC API
<= 4.7.4
16/05/2017
Host Header Injection in Password Reset
<= 4.7.4
03/05/2017
Path traversal
<= 4.5.3
12/07/2016
BYPASS #1
<= 4.5.2
23/06/2016
BYPASS #2
<= 4.5.2
23/06/2016
BYPASS #3
<= 4.5.2
23/06/2016
Denial of Service Attacks
<= 4.5.2
23/06/2016
Session Hijacking
<= 4.5.2
23/06/2016
XSS #1
<= 4.5.2
23/06/2016
XSS #2
<= 4.5.2
23/06/2016
BYPASS #4
<= 4.5.2
23/06/2016
XSS
<= 2.20.9
07/05/2016
XSS
<= 4.5.1
07/05/2016
Service Side Request Forgery
<= 4.4
15/04/2016
XSS
<= 4.4.1
12/04/2016
CSRF
<= 4.4.1
12/04/2016
XSS
<= 4.2.1
25/03/2016
SSRF
<= 4.4.1
05/02/2016
Open Redirect
<= 4.4.1
04/02/2016
Multiple XSS
<= 4.4.0
08/01/2016
XSS
<= 4.3.0
28/10/2015
XSS
<= 4.2.3
04/08/2015
XSS #1
<= 4.2.3
04/08/2015
XSS #2
<= 4.2.3
04/08/2015
CSRF
<= 4.2.3
04/08/2015
Multiple Vulnerabilities
<= 4.2.3
04/08/2015
BYPASS
<= 4.3.0
02/08/2015
XSS
<= 4.2.2
23/07/2015
XSS
<= 4.1.1
28/04/2015
Multiple XSS
<= 4.1.1
28/04/2015
Stored XSS
<= 4.2
27/04/2015
SQL Injection
<= 4.2.3
05/03/2015
Denial of Service Attacks
<= 4.0.1
01/12/2014
Multiple Vulnerabilities #1
<= 4.0.0
20/11/2014
SSRF
<= 4.0.0
20/11/2014
Multiple Vulnerabilities #2
<= 4.0.0
20/11/2014
XSS #1
<= 4.0.0
20/11/2014
XSS #2
<= 4.0.0
20/11/2014
CSRF
<= 4.0.0
20/11/2014
XSS #3
<= 4.0.0
20/11/2014
XSS
<= 3.9.2
20/11/2014
Denial Of Service Attacks #1
<= 3.9.1
15/08/2014
Denial Of Service Attacks #2
<= 3.9.1
15/08/2014
XSS
<= 3.9.1
14/08/2014
Multiple Vulnerabilities #1
<= 3.9.1
13/08/2014
Multiple Vulnerabilities #2
<= 3.9.1
13/08/2014
Unsafe Serialization
<= 3.9.1
13/08/2014
Information Disclosure
<= 3.3.2
20/01/2014
Multiple Vulnerabilities
<= 3.3.2
20/01/2014
Cross Site Scripting
<= 3.3.2
20/01/2014
Broken Access Control vulnerability
<= 3.0.5
20/01/2014
Admin+ Access Restriction Bypass vulnerability
<= 3.0.0
20/01/2014
BYPASS
<= 3.0.1
20/01/2014
XSS
<= 3.0.1
20/01/2014
Multiple XSS
<= 3.0.1
20/01/2014
Spam Restriction Bypass vulnerability
<= 3.0.1
20/01/2014
Cross Site Request Forgery
<= 2.0.11
17/12/2013
Multiple vulnerabilities
<= 3.8.1
03/12/2013
Privilege Escalation
<= 3.8.1
03/12/2013
URL Redirect Restriction Bypass
<= 3.6
14/10/2013
Cross Site Scripting #1
<= 3.6.0
11/09/2013
Cross Site Scripting #2
<= 3.6.0
11/09/2013
Privilege Escalation
<= 3.6.0
09/09/2013
Multiple vulnerabilities
<= 3.6.0
12/06/2013
Arbitrary Code Execution
<= 3.6.0
12/06/2013
Full Path Disclosure
<= 3.5.1
19/02/2013
XXE Injection
<= 3.5.1
19/02/2013
Multiple Cross Site Scripting
<= 3.5.1
19/02/2013
Privilege Escalation
<= 3.5.1
19/02/2013
Multiple SSRF
<= 3.5.1
19/02/2013
Denial of Service Attacks
<= 3.5.1
19/02/2013
Cross Site Scripting
<= 1.5.4
06/12/2012
Multiple Cross Site Scripting
<= 3.5.0
06/12/2012
SSRF
<= 3.5.0
06/12/2012
Session Identifier Leakage vulnerability
<= 3.4.2
14/11/2012
Multiple Path Dislosure Vulnerabilities
<= 3.4.2
18/09/2012
CSRF
<= 3.4.2
21/08/2012
Multiple vulnerabilities
<= 3.4.1
21/08/2012
BYPASS
<= 3.4.1
21/08/2012
Multiple Vulnerabilities
<= 3.4.0
14/06/2012
CSRF
<= 3.4.0
14/06/2012
XSS and BYPASS
<= 3.4.1
14/06/2012
BYPASS
<= 3.0.2
30/04/2012
Multiple CSRF Vulnerabilities
3.3.1
27/04/2012
XSS #1
<= 3.3.1
21/04/2012
XSS #2
<= 3.3.1
21/04/2012
BYPASS
<= 3.3.1
21/04/2012
CSRF and XSS
<= 3.3.1
21/04/2012
Unspecified vulnerability
<= 3.3.1
21/04/2012
Multiple Vulnerabilities
<= 3.3.1
25/01/2012
Multiple XSS
<= 3.3.1
18/01/2012
SQL injection
<= 0.7
04/01/2012
PHP remote file inclusion
<= 0.70
04/01/2012
Multiple Vulnerabilities
<= 3.1.0
23/12/2011
Cross Site Scripting
<= 3.1.0
23/12/2011
Information Disclosure Vulnerability
<= 3.0.4
23/09/2011
SQL Injection
<= 3.1.2
10/08/2011
Arbitrary File Upload vulnerability
<= 3.1.2
10/08/2011
Multiple vulnerabilities
<= 3.1.2
10/08/2011
Clickjacking Attacks
<= 3.1.2
10/08/2011
Multiple Unspecified Remote vulnerabilities
<= 3.1.2
10/08/2011
Unspecified vulnerability #1
<= 3.1.2
10/08/2011
Unspecified vulnerability #2
<= 3.1.2
10/08/2011
SQL Injection Vulnerabilities
<= 3.1.3
01/07/2011
Multiple Security Vulnerabilities
<= 3.0.4
31/01/2011
Multiple XSS
<= 3.0.4
31/01/2011
Stored XSS (IE6/7 NS8.1)
<= 3.0.3
29/12/2010
Multiple XSS
<= 3.0.3
09/12/2010
SQL Injection
<= 3.0.1
16/11/2010
Arbitrary Code Execution
<= 1.5.1.3
03/07/2010
Failure to Restrict URL Access
2.9,2.9.1
13/02/2010
DoS (0day)
<= 2.9
31/12/2009
Unrestricted File Upload Arbitrary PHP Code Execution
<= 2.8.5
11/11/2009
WordPress 2.0 - 2.7.1 - Module Configuration Security Bypass Vulnerability
2.0-2.7.1
10/11/2009
XSS
<= 2.8.5
05/11/2009
Algorithmic complexity
<= 2.8.4
09/10/2009
Multiple Vulnerabilities #2
<= 2.8.2
18/08/2009
Multiple Vulnerabilities #1
<= 2.8.2
18/08/2009
BYPASS
<= 2.8.2
13/08/2009
Remote Cross-Site Scripting Vulnerability
2.8.1
24/07/2009
Privileges Unchecked in admin.php and Multiple Information
<= 2.8
10/07/2009
Multiple vulnerabilities
<= 2.8.0
10/07/2009
Information Disclosure
<= 2.7.1
10/07/2009
Multiple Existing/Non-Existing Username Enumeration Weaknesses
<= 2.8.0
05/07/2009
Denial Of Service Attacks
<= 2.6.9
28/04/2009
Open Redirection
<= 2.6.9
28/04/2009
Remote Code Execution
<= 1.3.1
19/12/2008
Cross Site Request Forgery
<= 2.6.3
17/11/2008
Directory Traversal
<= 2.3.3
27/10/2008
SQL Truncation Vulnerability #1
<= 2.6.1
15/09/2008
SQL Truncation Vulnerability #2
<= 2.6.1
15/09/2008
Multiple vulnerabilities
<= 2.6.0
20/08/2008
XSS
<= 2.5
18/07/2008
Unrestricted file upload
<= 2.5.1
21/05/2008
BYPASS
<= 2.2.2
12/05/2008
XSS
<= 2.5
02/05/2008
Cookie Integrity Protection Vulnerability
<= 2.5
23/04/2008
Multiple XSS vulnerabilities
<= 2.3.2
12/03/2008
Unauthorized Access Vulnerability
<= 2.3.2
07/02/2008
Multiple Directory Traversal
<= 2.0.11
09/01/2008
Multiple Vulnerabilities
<= 2.0.11
09/01/2008
Directory Traversal
<= 2.0.3
09/01/2008
XSS
<= 2.0.11
09/01/2008
Multiple XSS
<= 2.0.9
09/01/2008
SQL Injection
<= 2.3.9
09/01/2008
SQL Injection
<= 2.3.1
11/12/2007
Cookie Authentication Vulnerability
<= 2.3.1
19/11/2007
XSS
<= 2.3
30/10/2007
Cross Site Scripting
<= 2.0
26/09/2007
XSS
<= 2.0.1
26/09/2007
Multiple SQL Injection
<= 2.2.3
14/09/2007
XSS
<= 2.2.3
14/09/2007
SQL Injection
<= 2.2.1
03/08/2007
Multiple XSS
<= 2.2.1
03/08/2007
XSS
<= 2.2.1
02/08/2007
Multiple vulnerabilities
<= 2.2.1
09/07/2007
Arbitrary File Upload
<= 2.2.1
03/07/2007
Arbitrary File Upload
<= 2.2.0
03/07/2007
SQL Injection
<= 2.2
08/06/2007
SQL Injection
<= 2.1
22/05/2007
Cross Site Scripting
<= 1.0
11/05/2007
SQL Injection vulnerability
<= 2.1.2
09/04/2007
XSS
<= 2.0.10
09/04/2007
Security BYPASS
<= 2.1.2
09/04/2007
Cross Site Scripting
<= 2.1.2
28/03/2007
XSS
<= 2.1.2 RC2
22/03/2007
Redirection Vulnerability
<= 1.0
22/03/2007
Sensitive Directory Exposure
<= 2.1.2
10/03/2007
Multiple Vulnerabilities
<= 2.1.1
05/03/2007
Multiple XSS
<= 2.1.1
02/03/2007
XSS
<= 2.1.0
21/02/2007
Multiple Vulnerabilities
<= 1.4.5
29/01/2007
Denial of Service Attacks
<= 2.1
29/01/2007
Denial of Service Attacks
<= 2.0
29/01/2007
Full Path disclosure
<= 2.0.6
16/01/2007
SQL Injection vulnerability
<= 2.0.6
12/01/2007
Dictionnary & Bruteforce attack
<= 2.0.5
08/01/2007
SQL Injection
<= 2.0.5
08/01/2007
XSS
<= 2.0.5
08/01/2007
Cross Site Scripting
<= 2.0.5
28/12/2006
Denial of Service Attacks
<= 2.0.4
21/11/2006
Multiple vulnerabilities
<= 2.0.4
21/11/2006
Multiple Directory Traversal
<= 2.0.4
03/11/2006
Multiple vulnerabilities #1
<= 2.0.5
13/09/2006
Multiple Vulnerabilities
<= 2.0.3
09/08/2006
Full Path Disclosure
<= 2.0.3
06/07/2006
Direct Static Code Injection
<= 2.0.2
30/05/2006
Shell Injection
<= 2.0.2
30/05/2006
Cross Site Scripting (XSS)
<= 1.5.2
17/04/2006
Multiple XSS
<= 2.0.1
18/03/2006
SQL injection
<= 1.5.2
06/03/2006
Multiple XSS
<= 2.0.1
03/03/2006
Multiple Vulnerabilities
<= 2.0.1
03/03/2006
Cross Site Scripting
<= 2.0.0
16/02/2006
Multiple Vulnerabilities
<= 1.5.1
21/12/2005
Remote Code Execution
<= 1.2
27/10/2005
Multiple XSS vulnerabilities
<= 1.5.1.2
01/07/2005
SQL injection
<= 1.5.1.2
01/07/2005
Multiple Vulnerabilities #1
<= 1.5.1.2
01/07/2005
Multiple Vulnerabilities #2
<= 1.5.1.2
01/07/2005
Eval Injection
1.3
08/06/2005
SQL injection
<= 1.5.1
01/06/2005
SQL injection vulnerability
<= 1.5
20/05/2005
SQL injection vulnerability
<= 1.5
20/05/2005
Multiple Cross-Site Scripting (XSS) vulnerabilities
<= 1.5
13/04/2005
Multiple Cross-Site Scripting (XSS) vulnerabilities
<= 1.2
20/02/2005
CRLF (Carriage Return Line Feed) injection
<= 1.2
20/02/2005