Cross-Site Scripting
137 records37.1%First: 2004. Latest: 2026.
WordPress Core security history
The Wordfence Intelligence dataset currently contains 369 vulnerability records associated with WordPress, published between 2003 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2003 | 2 | |
| 2004 | 2 | |
| 2005 | 10 | |
| 2006 | 14 | |
| 2007 | 40 | |
| 2008 | 12 | |
| 2009 | 12 | |
| 2010 | 9 | |
| 2011 | 13 | |
| 2012 | 19 | |
| 2013 | 17 | |
| 2014 | 19 | |
| 2015 | 17 | |
| 2016 | 21 | |
| 2017 | 41 | |
| 2018 | 16 | |
| 2019 | 22 | |
| 2020 | 22 | |
| 2021 | 10 | |
| 2022 | 22 | |
| 2023 | 14 | |
| 2024 | 5 | |
| 2025 | 2 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 16 | 4.3% |
| High | 92 | 24.9% |
| Medium | 243 | 65.9% |
| Low | 8 | 2.2% |
| Informational | 10 | 2.7% |
First: 2004. Latest: 2026.
First: 2003. Latest: 2026.
First: 2006. Latest: 2026.
First: 2005. Latest: 2024.
First: 2003. Latest: 2026.
First: 2007. Latest: 2023.
First: 2006. Latest: 2024.
First: 2007. Latest: 2018.
First: 2007. Latest: 2020.
First: 2007. Latest: 2020.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.8.67.0.26.9.56.9.26.8.46.8.36.7.46.6.46.5.76.4.76.3.76.2.86.1.96.0.115.9.125.8.125.7.145.6.165.5.175.4.185.3.205.2.235.1.215.0.244.9.284.8.274.7.315.8.105.7.125.6.145.5.155.4.165.3.185.2.215.1.195.0.224.9.264.8.254.7.294.6.294.5.324.4.334.3.344.2.384.1.416.5.56.4.56.3.56.2.66.1.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
3.9-3.9.3 | WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload | April 20, 2015 | 3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2 | Medium |
3.8-3.8.5 | WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload | April 20, 2015 | 3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2 | Medium |
3.7-3.7.5 | WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload | April 20, 2015 | 3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2 | Medium |
[*, 3.7) | WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload | April 20, 2015 | 3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2 | Medium |
4.2-4.2.1 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
4.1-4.1.4 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
4.0-4.0.4 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
3.9-3.9.5 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
3.8-3.8.7 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
3.7-3.7.7 | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
[*, 3.7) | Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html | April 8, 2015 | 3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2 | Medium |
[*, 4.4) | WordPress Core < 4.4 - Brute Force Password Recovery Tokens | February 12, 2015 | 4.4 | High |
4.0 | WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
3.9-3.9.2 | WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
3.8-3.8.4 | WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
3.7-3.7.4 | WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
[*, 3.7) | WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
4.0 | WordPress Core < 4.0.1 - Cross-Site Scripting | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | Medium |
3.9-3.9.2 | WordPress Core < 4.0.1 - Cross-Site Scripting | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | Medium |
3.8-3.8.4 | WordPress Core < 4.0.1 - Cross-Site Scripting | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | Medium |
3.7-3.7.4 | WordPress Core < 4.0.1 - Cross-Site Scripting | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | Medium |
[*, 3.7) | WordPress Core < 4.0.1 - Cross-Site Scripting | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | Medium |
4.0 | WordPress Core < 4.0.1 Cross-Site Request Forgery to Password Reset | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
3.9-3.9.2 | WordPress Core < 4.0.1 Cross-Site Request Forgery to Password Reset | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
3.8-3.8.4 | WordPress Core < 4.0.1 Cross-Site Request Forgery to Password Reset | November 20, 2014 | 3.7.5, 3.8.5, 3.9.3, 4.0.1 | High |
Selected source records
Published: July 17, 2026
Published: July 17, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: July 17, 2026
Published: July 9, 2006
Published: September 8, 2007
Published: October 29, 2020
Published: March 2, 2007
Published: September 19, 2017
Published: September 8, 2007
Published: December 6, 2023
Published: September 6, 2022
Published: October 10, 2017
The WordPress Core vulnerability history is long-running and varied rather than concentrated in a single release or weakness. The synchronized dataset contains 369 records published from June 2003 through July 2026. Cross-site scripting is the largest normalized category with 137 records (37.1%), followed by 40 missing-authorization and 36 information-disclosure records. The history also includes 16 critical and 92 high-severity records.
The latest records materially affect how this history should be read. The dataset identifies a critical remote-code-execution record affecting the 6.9 and 7.0 branches before 6.9.5 and 7.0.2, together with a high-severity SQL-injection record affecting several maintained branches. This demonstrates why WordPress Core maintenance should follow the supported release branch and security releases, not simply a fixed calendar schedule.
Of the 369 associated records, 367 are marked patched and two are currently marked unpatched in the synchronized source. Those counts describe source records; they do not establish that a particular website is exposed or compromised.
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.