WordPress Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for WordPress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

2

Beyond CISA KEV

3

Sensor Observed

1

Virtual Patch Available

1

WordPress KEVs Added by Year

Loading...

5 WordPress KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-63030

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

Confirmed In CISA 17 Jul 2026
CVE-2026-60137

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Confirmed In CISA 17 Jul 2026
CVE-2022-21661

SQL injection in WordPress

High Not in CISA 06 Jan 2022
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an...

High Not in CISA 30 Jul 2026
CVE-2017-1001000

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2...

High Not in CISA 09 Feb 2017

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-436 — Interpretation Conflict 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology