Cross-Site Scripting
137 records37.1%First: 2004. Latest: 2026.
WordPress Core security history
The Wordfence Intelligence dataset currently contains 369 vulnerability records associated with WordPress, published between 2003 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2003 | 2 | |
| 2004 | 2 | |
| 2005 | 10 | |
| 2006 | 14 | |
| 2007 | 40 | |
| 2008 | 12 | |
| 2009 | 12 | |
| 2010 | 9 | |
| 2011 | 13 | |
| 2012 | 19 | |
| 2013 | 17 | |
| 2014 | 19 | |
| 2015 | 17 | |
| 2016 | 21 | |
| 2017 | 41 | |
| 2018 | 16 | |
| 2019 | 22 | |
| 2020 | 22 | |
| 2021 | 10 | |
| 2022 | 22 | |
| 2023 | 14 | |
| 2024 | 5 | |
| 2025 | 2 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 16 | 4.3% |
| High | 92 | 24.9% |
| Medium | 243 | 65.9% |
| Low | 8 | 2.2% |
| Informational | 10 | 2.7% |
First: 2004. Latest: 2026.
First: 2003. Latest: 2026.
First: 2006. Latest: 2026.
First: 2005. Latest: 2024.
First: 2003. Latest: 2026.
First: 2007. Latest: 2023.
First: 2006. Latest: 2024.
First: 2007. Latest: 2018.
First: 2007. Latest: 2020.
First: 2007. Latest: 2020.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.8.67.0.26.9.56.9.26.8.46.8.36.7.46.6.46.5.76.4.76.3.76.2.86.1.96.0.115.9.125.8.125.7.145.6.165.5.175.4.185.3.205.2.235.1.215.0.244.9.284.8.274.7.315.8.105.7.125.6.145.5.155.4.165.3.185.2.215.1.195.0.224.9.264.8.254.7.294.6.294.5.324.4.334.3.344.2.384.1.416.5.56.4.56.3.56.2.66.1.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
5.9-5.9.11 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.8-5.8.11 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.7-5.7.13 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.6-5.6.15 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.5-5.5.16 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.4-5.4.17 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.3-5.3.19 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.2-5.2.22 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.1-5.1.20 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.0-5.0.23 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
4.9-4.9.27 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
4.8-4.8.26 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
4.7-4.7.30 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
*-4.7 | WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.8-6.8.2 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.7-6.7.3 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.6-6.6.3 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.5-6.5.6 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.4-6.4.6 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.3-6.3.6 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.2-6.2.7 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.1-6.1.8 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
6.0-6.0.10 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.9-5.9.11 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
5.8-5.8.11 | WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 22, 2025 | 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3 | Medium |
Selected source records
Published: July 17, 2026
Published: July 17, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: July 17, 2026
Published: July 9, 2006
Published: September 8, 2007
Published: October 29, 2020
Published: March 2, 2007
Published: September 19, 2017
Published: September 8, 2007
Published: December 6, 2023
Published: September 6, 2022
Published: October 10, 2017
The WordPress Core vulnerability history is long-running and varied rather than concentrated in a single release or weakness. The synchronized dataset contains 369 records published from June 2003 through July 2026. Cross-site scripting is the largest normalized category with 137 records (37.1%), followed by 40 missing-authorization and 36 information-disclosure records. The history also includes 16 critical and 92 high-severity records.
The latest records materially affect how this history should be read. The dataset identifies a critical remote-code-execution record affecting the 6.9 and 7.0 branches before 6.9.5 and 7.0.2, together with a high-severity SQL-injection record affecting several maintained branches. This demonstrates why WordPress Core maintenance should follow the supported release branch and security releases, not simply a fixed calendar schedule.
Of the 369 associated records, 367 are marked patched and two are currently marked unpatched in the synchronized source. Those counts describe source records; they do not establish that a particular website is exposed or compromised.
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.