Cross-Site Scripting
137 records37.1%First: 2004. Latest: 2026.
WordPress Core security history
The Wordfence Intelligence dataset currently contains 369 vulnerability records associated with WordPress, published between 2003 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2003 | 2 | |
| 2004 | 2 | |
| 2005 | 10 | |
| 2006 | 14 | |
| 2007 | 40 | |
| 2008 | 12 | |
| 2009 | 12 | |
| 2010 | 9 | |
| 2011 | 13 | |
| 2012 | 19 | |
| 2013 | 17 | |
| 2014 | 19 | |
| 2015 | 17 | |
| 2016 | 21 | |
| 2017 | 41 | |
| 2018 | 16 | |
| 2019 | 22 | |
| 2020 | 22 | |
| 2021 | 10 | |
| 2022 | 22 | |
| 2023 | 14 | |
| 2024 | 5 | |
| 2025 | 2 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 16 | 4.3% |
| High | 92 | 24.9% |
| Medium | 243 | 65.9% |
| Low | 8 | 2.2% |
| Informational | 10 | 2.7% |
First: 2004. Latest: 2026.
First: 2003. Latest: 2026.
First: 2006. Latest: 2026.
First: 2005. Latest: 2024.
First: 2003. Latest: 2026.
First: 2007. Latest: 2023.
First: 2006. Latest: 2024.
First: 2007. Latest: 2018.
First: 2007. Latest: 2020.
First: 2007. Latest: 2020.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.8.67.0.26.9.56.9.26.8.46.8.36.7.46.6.46.5.76.4.76.3.76.2.86.1.96.0.115.9.125.8.125.7.145.6.165.5.175.4.185.3.205.2.235.1.215.0.244.9.284.8.274.7.315.8.105.7.125.6.145.5.155.4.165.3.185.2.215.1.195.0.224.9.264.8.254.7.294.6.294.5.324.4.334.3.344.2.384.1.416.5.56.4.56.3.56.2.66.1.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.0.2 | WordPress Core < 2.0.3 - IP Address Spoofing | June 1, 2006 | 2.0.3 | Medium |
*-2.0.1 | WordPress Core <= 2.0.1 - Cross-Site Scripting | March 10, 2006 | 2.0.2 | High |
[*, 2.0.2) | WordPress Core < 2.0.2 - Reflected Cross-Site Scripting | March 10, 2006 | 2.0.2 | Medium |
[*, 2.0.2) | WordPress Core < 2.0.2 - Cross-Site Scripting | March 10, 2006 | 2.0.2 | Medium |
*-2.0.1 | WordPress Core < 2.0.2 - Sensitive Information Disclosure | March 10, 2006 | 2.0.2 | High |
*-2.0 | WordPress Core < 2.0.1 - Cross-Site Scripting | January 31, 2006 | 2.0.1 | Medium |
*-1.5.2 | WordPress Core <= 1.5.2 - SQL Injection | December 31, 2005 | 2.0 | High |
*-1.5.1.3 | WordPress Core < 1.5.2 - Remote Code Execution | August 9, 2005 | 1.5.2 | High |
*-1.5.1.2 | WordPress Core < 1.5.1.3 - Arbitrary Email Content Change | June 29, 2005 | 1.5.1.3 | Medium |
*-1.5.1.2 | WordPress Core < 1.5.1.3 - Sensitive Information Disclosure | June 29, 2005 | 1.5.1.3 | High |
*-1.5.1.2 | WordPress Core <= 1.5.1.2 - Cross-Site Scripting | June 29, 2005 | 1.5.1.3 | High |
[*, 1.5.1.3) | WordPress Core < 1.5.1.3 - SQL Injection | June 29, 2005 | 1.5.1.3 | High |
*-1.5.1 | WordPress Core <= 1.5 - Stored Cross-Site Scripting | June 27, 2005 | 1.5.1.2 | Medium |
*-1.5.1.1 | WordPress Core < 1.5.1.2 - SQL Injection | May 27, 2005 | 1.5.1.2 | High |
[*, 1.5.1) | WordPress Core < 1.5.1 - SQL Injection | May 9, 2005 | 1.5.1 | High |
[*, 1.5.1) | WordPress Core < 1.5.1 - Full Path Disclosure | May 9, 2005 | 1.5.1 | Medium |
[*, 1.2.1) | WordPress Core <= 1.2 - HTTP Response Splitting | October 6, 2004 | 1.2.1 | Medium |
[*, 1.2) | WordPress Core < 1.2.1 - Cross-Site Scripting | October 6, 2004 | 1.2 | Medium |
[*, 0.72) | WordPress Core < 0.72 - SQL Injection | October 11, 2003 | 0.72 | High |
*-0.70 | WordPress Core <= 0.70 - Remote File Inclusion | June 9, 2003 | 0.71 | Critical |
Selected source records
Published: July 17, 2026
Published: July 17, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: July 17, 2026
Published: July 9, 2006
Published: September 8, 2007
Published: October 29, 2020
Published: March 2, 2007
Published: September 19, 2017
Published: September 8, 2007
Published: December 6, 2023
Published: September 6, 2022
Published: October 10, 2017
The WordPress Core vulnerability history is long-running and varied rather than concentrated in a single release or weakness. The synchronized dataset contains 369 records published from June 2003 through July 2026. Cross-site scripting is the largest normalized category with 137 records (37.1%), followed by 40 missing-authorization and 36 information-disclosure records. The history also includes 16 critical and 92 high-severity records.
The latest records materially affect how this history should be read. The dataset identifies a critical remote-code-execution record affecting the 6.9 and 7.0 branches before 6.9.5 and 7.0.2, together with a high-severity SQL-injection record affecting several maintained branches. This demonstrates why WordPress Core maintenance should follow the supported release branch and security releases, not simply a fixed calendar schedule.
Of the 369 associated records, 367 are marked patched and two are currently marked unpatched in the synchronized source. Those counts describe source records; they do not establish that a particular website is exposed or compromised.
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.