WordPress Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for WordPress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
2
Beyond CISA KEV
3
Sensor Observed
1
Virtual Patch Available
1
WordPress KEVs Added by Year
5 WordPress KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution |
WordPress | Confirmed | In CISA | 17 Jul 2026 |
|
CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query |
WordPress | Confirmed | In CISA | 17 Jul 2026 |
|
CVE-2022-21661
SQL injection in WordPress |
wordpress-develop | High | Not in CISA | 06 Jan 2022 |
|
CVE-2019-8942
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an... |
WordPress | High | Not in CISA | 30 Jul 2026 |
|
CVE-2017-1001000
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2... |
WordPress | High | Not in CISA | 09 Feb 2017 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-436 — Interpretation Conflict 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology