wordpress has 2 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 6.2 (medium).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 50% vs 1% corpus
- Median CVSS
- 6.2
- Publish → KEV
- —(1)
- Last 90 days
- 1 prev 0
2
Total CVEs
0
Critical
1
CISA KEV
1
Exploited
Worst active — by depth score
CVE-2026-87902High· 8.1An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories79CVE-2023-39999Medium· 4.3Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…24
wordpress vulnerabilities
CVEs affecting wordpress, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-87902High· 8.1CISA KEVPoCAn unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are…
▾ Abyssalwordpress · wordpressEPSS 46%via NVD
CVE-2023-39999Medium· 4.3Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…
▾ Sunlitwordpress · wordpressEPSS 1.0%via NVD