Cross-Site Scripting
137 records37.1%First: 2004. Latest: 2026.
WordPress Core security history
The Wordfence Intelligence dataset currently contains 369 vulnerability records associated with WordPress, published between 2003 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2003 | 2 | |
| 2004 | 2 | |
| 2005 | 10 | |
| 2006 | 14 | |
| 2007 | 40 | |
| 2008 | 12 | |
| 2009 | 12 | |
| 2010 | 9 | |
| 2011 | 13 | |
| 2012 | 19 | |
| 2013 | 17 | |
| 2014 | 19 | |
| 2015 | 17 | |
| 2016 | 21 | |
| 2017 | 41 | |
| 2018 | 16 | |
| 2019 | 22 | |
| 2020 | 22 | |
| 2021 | 10 | |
| 2022 | 22 | |
| 2023 | 14 | |
| 2024 | 5 | |
| 2025 | 2 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 16 | 4.3% |
| High | 92 | 24.9% |
| Medium | 243 | 65.9% |
| Low | 8 | 2.2% |
| Informational | 10 | 2.7% |
First: 2004. Latest: 2026.
First: 2003. Latest: 2026.
First: 2006. Latest: 2026.
First: 2005. Latest: 2024.
First: 2003. Latest: 2026.
First: 2007. Latest: 2023.
First: 2006. Latest: 2024.
First: 2007. Latest: 2018.
First: 2007. Latest: 2020.
First: 2007. Latest: 2020.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.8.67.0.26.9.56.9.26.8.46.8.36.7.46.6.46.5.76.4.76.3.76.2.86.1.96.0.115.9.125.8.125.7.145.6.165.5.175.4.185.3.205.2.235.1.215.0.244.9.284.8.274.7.315.8.105.7.125.6.145.5.155.4.165.3.185.2.215.1.195.0.224.9.264.8.254.7.294.6.294.5.324.4.334.3.344.2.384.1.416.5.56.4.56.3.56.2.66.1.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[*, 3.7) | WordPress Core < 3.9.2 - Denial of Service via XML | August 6, 2014 | 3.7.4, 3.8.4, 3.9.2 | Low |
3.9-3.9.1 | WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass | August 6, 2014 | 3.7.4, 3.8.4, 3.9.2 | High |
3.8-3.8.3 | WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass | August 6, 2014 | 3.7.4, 3.8.4, 3.9.2 | High |
3.7-3.7.3 | WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass | August 6, 2014 | 3.7.4, 3.8.4, 3.9.2 | High |
[*, 3.7) | WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass | August 6, 2014 | 3.7.4, 3.8.4, 3.9.2 | High |
[*, 3.9.2) | WordPress Core <= 3.9.1 - XML External Entity (XXE) Weakness | August 6, 2014 | 3.9.2 | Medium |
3.8.1 | WordPress Core < 3.8.2 - SQL Injection | April 9, 2014 | 3.8.2 | High |
3.8-3.8.1 | WordPress Core < 3.8.2 - Authentication Cookie Forgery | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
3.7-3.7.1 | WordPress Core < 3.8.2 - Authentication Cookie Forgery | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
[*, 3.7) | WordPress Core < 3.8.2 - Authentication Cookie Forgery | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
3.8-3.8.1 | WordPress Core < 3.8.2 - Contributor Users Can Publish Posts | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
3.7-3.7.1 | WordPress Core < 3.8.2 - Contributor Users Can Publish Posts | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
[*, 3.7) | WordPress Core < 3.8.2 - Contributor Users Can Publish Posts | April 8, 2014 | 3.7.2, 3.8.2 | Medium |
*-2.0.11 | WordPress Core < 2.1 - Cross-Site Request Forgery to Denial of Service | December 17, 2013 | 2.1 | High |
*-3.6 | WordPress Core < 3.6.1 - Deserialization | September 11, 2013 | 3.6.1 | High |
*-3.6 | WordPress Core < 3.6.1 - Spoof Post Authorship | September 11, 2013 | 3.6.1 | Medium |
[*, 3.6.1) | WordPress Core < 3.6.1 - .swf and .exe File Upload | September 11, 2013 | 3.6.1 | Medium |
*-3.6 | WordPress Core < 3.6.1 - HTML File Upload | September 11, 2013 | 3.6.1 | Medium |
*-3.6 | WordPress Core < 3.6.1 - Open Redirect | September 11, 2013 | 3.6.1 | Medium |
*-3.5.1 | WordPress Core < 3.5.2 - Missing Authorization Checks | June 21, 2013 | 3.5.2 | Medium |
*-3.5.1 | WordPress Core < 3.5.2 - Sensitive Information Disclosure | June 21, 2013 | 3.5.2 | Medium |
*-3.5.1 | WordPress Core < 3.5.2 - Cross-Site Scripting | June 21, 2013 | 3.5.2 | Medium |
[*, 3.5.2) | WordPress Core <= 3.5.1 - Denial of Service via wp-postpass cookie | June 21, 2013 | 3.5.2 | Medium |
*-3.5.1 | WordPress Core < 3.5.2 - Server Side Request Forgery | June 21, 2013 | 3.5.2 | Medium |
*-3.5.1 | WordPress Core < 3.5.2 - Cross-Site Scripting via Multiple Vectors | June 21, 2013 | 3.5.2 | Medium |
Selected source records
Published: July 17, 2026
Published: July 17, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: July 17, 2026
Published: July 9, 2006
Published: September 8, 2007
Published: October 29, 2020
Published: March 2, 2007
Published: September 19, 2017
Published: September 8, 2007
Published: December 6, 2023
Published: September 6, 2022
Published: October 10, 2017
The WordPress Core vulnerability history is long-running and varied rather than concentrated in a single release or weakness. The synchronized dataset contains 369 records published from June 2003 through July 2026. Cross-site scripting is the largest normalized category with 137 records (37.1%), followed by 40 missing-authorization and 36 information-disclosure records. The history also includes 16 critical and 92 high-severity records.
The latest records materially affect how this history should be read. The dataset identifies a critical remote-code-execution record affecting the 6.9 and 7.0 branches before 6.9.5 and 7.0.2, together with a high-severity SQL-injection record affecting several maintained branches. This demonstrates why WordPress Core maintenance should follow the supported release branch and security releases, not simply a fixed calendar schedule.
Of the 369 associated records, 367 are marked patched and two are currently marked unpatched in the synchronized source. Those counts describe source records; they do not establish that a particular website is exposed or compromised.
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.