Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress Core security history

WordPress Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 369 vulnerability records associated with WordPress, published between 2003 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

369Total records
16Critical
92High
243Medium
8Low
10Informational
367Patched records
2Currently marked unpatched
2003-06-09First disclosure
2026-07-17Latest disclosure
340 of 369CVE coverage
368Network attack vector
147No privileges required
298No user interaction

Year-by-Year Timeline

YearRecordsRelative volume
200322 records
200422 records
20051010 records
20061414 records
20074040 records
20081212 records
20091212 records
201099 records
20111313 records
20121919 records
20131717 records
20141919 records
20151717 records
20162121 records
20174141 records
20181616 records
20192222 records
20202222 records
20211010 records
20222222 records
20231414 records
202455 records
202522 records
202688 records

Severity Breakdown

SeverityRecordsShare
Critical164.3%
High9224.9%
Medium24365.9%
Low82.2%
Informational102.7%

Vulnerability-Type Breakdown

Cross-Site Scripting

137 records37.1%

First: 2004. Latest: 2026.

Other

88 records23.8%

First: 2003. Latest: 2026.

Missing Authorization

40 records10.8%

First: 2006. Latest: 2026.

Information Disclosure

36 records9.8%

First: 2005. Latest: 2024.

SQL Injection

24 records6.5%

First: 2003. Latest: 2026.

CSRF

17 records4.6%

First: 2007. Latest: 2023.

Path Traversal

10 records2.7%

First: 2006. Latest: 2024.

Arbitrary File Upload

7 records1.9%

First: 2007. Latest: 2018.

Privilege Escalation

6 records1.6%

First: 2007. Latest: 2020.

Authentication Bypass

4 records1.1%

First: 2007. Latest: 2020.

Patch Status

Patched
367
Currently marked unpatched
2
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.8.6
  • 7.0.2
  • 6.9.5
  • 6.9.2
  • 6.8.4
  • 6.8.3
  • 6.7.4
  • 6.6.4
  • 6.5.7
  • 6.4.7
  • 6.3.7
  • 6.2.8
  • 6.1.9
  • 6.0.11
  • 5.9.12
  • 5.8.12
  • 5.7.14
  • 5.6.16
  • 5.5.17
  • 5.4.18
  • 5.3.20
  • 5.2.23
  • 5.1.21
  • 5.0.24
  • 4.9.28
  • 4.8.27
  • 4.7.31
  • 5.8.10
  • 5.7.12
  • 5.6.14
  • 5.5.15
  • 5.4.16
  • 5.3.18
  • 5.2.21
  • 5.1.19
  • 5.0.22
  • 4.9.26
  • 4.8.25
  • 4.7.29
  • 4.6.29
  • 4.5.32
  • 4.4.33
  • 4.3.34
  • 4.2.38
  • 4.1.41
  • 6.5.5
  • 6.4.5
  • 6.3.5
  • 6.2.6
  • 6.1.7

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
5.9-5.9.11WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.8-5.8.11WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.7-5.7.13WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.6-5.6.15WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.5-5.5.16WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.4-5.4.17WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.3-5.3.19WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.2-5.2.22WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.1-5.1.20WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.0-5.0.23WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
4.9-4.9.27WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
4.8-4.8.26WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
4.7-4.7.30WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
*-4.7WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site ScriptingSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.8-6.8.2WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.7-6.7.3WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.6-6.6.3WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.5-6.5.6WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.4-6.4.6WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.3-6.3.6WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.2-6.2.7WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.1-6.1.8WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
6.0-6.0.10WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.9-5.9.11WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium
5.8-5.8.11WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information ExposureSeptember 22, 20254.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3Medium

Selected source records

Latest Records

CriticalCVE-2026-63030

WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion

Published: July 17, 2026

Affected versions
[6.9, 6.9.5); [7.0, 7.0.2)
Patched versions
6.9.5, 7.0.2
Original Wordfence record
HighCVE-2026-60137

WordPress Core 6.8 - 7.0.1 - Unauthenticated SQL Injection via author__not_in Parameter

Published: July 17, 2026

Affected versions
[6.8, 6.8.5); [6.9, 6.9.5); [7.0, 7.0.2)
Patched versions
6.8.6, 6.9.5, 7.0.2
Original Wordfence record
Medium

WordPress <= 6.9.1 - Missing Authorization to Authenticated (Author+) Sensitive Information Disclosure via query-attachments AJAX Endpoint

Published: March 10, 2026

Affected versions
6.8-6.8.3; 6.9-6.9.1
Patched versions
6.8.4, 6.9.2
Original Wordfence record
Medium

WordPress <= 6.9.1 - Unauthenticated Blind Server-Side Request Forgery via XML-RPC Pingback Discovery

Published: March 10, 2026

Affected versions
6.8-6.8.3; 6.9-6.9.1
Patched versions
6.8.4, 6.9.2
Original Wordfence record
Medium

WordPress <= 6.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Navigation Menu Items

Published: March 10, 2026

Affected versions
6.8-6.8.3; 6.9-6.9.1
Patched versions
6.8.4, 6.9.2
Original Wordfence record
Medium

WordPress <= 6.9.1 - Cross-Site Scripting via Client-Side Template Override in Admin Area

Published: March 10, 2026

Affected versions
6.8-6.8.3; 6.9-6.9.1
Patched versions
6.8.4, 6.9.2
Original Wordfence record
MediumCVE-2026-3906

WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API

Published: March 10, 2026

Affected versions
6.9-6.9.1
Patched versions
6.9.2
Original Wordfence record
Medium

WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload

Published: March 10, 2026

Affected versions
6.8-6.8.3; 6.9-6.9.1
Patched versions
6.8.4, 6.9.2
Original Wordfence record

Highest-Severity Records

CriticalCVE-2026-63030

WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion

Published: July 17, 2026

Affected versions
[6.9, 6.9.5); [7.0, 7.0.2)
Patched versions
6.9.5, 7.0.2
Original Wordfence record
CriticalCVE-2006-4028

WordPress Core < 2.0.4 - Privilege Escalation

Published: July 9, 2006

Affected versions
[*, 2.0.4)
Patched versions
2.0.4
Original Wordfence record
CriticalCVE-2007-6318

WordPress Core < 2.3.2 - SQL Injection

Published: September 8, 2007

Affected versions
*-2.3.1
Patched versions
2.3.2
Original Wordfence record
CriticalCVE-2021-29476

WordPress Core < 5.5.3 - PHP Object Injection Gadget

Published: October 29, 2020

Affected versions
[*, 3.7); [3.7, 3.7.35); [3.8, 3.8.35); [3.9, 3.9.33); [4.0, 4.0.32); [4.1, 4.1.32); [4.2, 4.2.29); [4.3, 4.3.25); [4.4, 4.4.24); [4.5, 4.5.23); [4.6, 4.6.20); [4.7, 4.7.19); [4.8, 4.8.15); [4.9, 4.9.16); [5.0, 5.0.11); [5.1, 5.1.8); [5.2, 5.2.9); [5.3, 5.3.6); [5.4, 5.4.4); [5.5, 5.5.3)
Patched versions
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.8, 5.2.9, 5.3.6, 5.4.4, 5.5.3
Original Wordfence record
Critical

WordPress Core 2.1.1 - Supply Chain Compromise

Published: March 2, 2007

Affected versions
2.1.1
Patched versions
2.1.2
Original Wordfence record
CriticalCVE-2017-14723

WordPress Core < 4.8.2 - SQL Injection via Mishandled Placeholders

Published: September 19, 2017

Affected versions
[*, 3.7); 3.7-3.7.21; 3.8-3.8.21; 3.9-3.9.19; 4.0-4.0.18; 4.1-4.1.18; 4.2-4.2.15; 4.3-4.3.11; 4.4-4.4.10; 4.5-4.5.9; 4.6-4.6.6; 4.7-4.7.5; 4.8-4.8.1
Patched versions
3.7.22, 3.8.22, 3.9.20, 4.0.19, 4.1.19, 4.2.16, 4.3.12, 4.4.11, 4.5.10, 4.6.7, 4.7.6, 4.8.2
Original Wordfence record
CriticalCVE-2007-4894

WordPress Core < 2.2.3 & WordPress MU < 1.2.5a - SQL Injection

Published: September 8, 2007

Affected versions
[*, 1.2.5)
Patched versions
1.2.5
Affected versions
[*, 2.2.3)
Patched versions
2.2.3
Original Wordfence record
CriticalCVE-2024-31211

WordPress Core 6.4.0 - 6.4.1 - Remote Code Execution POP Chain

Published: December 6, 2023

Affected versions
6.4.0; 6.4.1
Patched versions
6.4.2
Original Wordfence record

Currently Marked Unpatched Records

InformationalCVE-2022-3590

WordPress Core - All known versions - Unauthenticated Blind Server Side Request Forgery

Published: September 6, 2022

Affected versions
*
Patched versions
Not supplied
Original Wordfence record
InformationalCVE-2017-14990

WordPress Core - All Known Versions - Cleartext Storage of wp_signups.activation_key

Published: October 10, 2017

Affected versions
*
Patched versions
Not supplied
Original Wordfence record

View all associated vulnerabilities

3Zero Interpretation

The WordPress Core vulnerability history is long-running and varied rather than concentrated in a single release or weakness. The synchronized dataset contains 369 records published from June 2003 through July 2026. Cross-site scripting is the largest normalized category with 137 records (37.1%), followed by 40 missing-authorization and 36 information-disclosure records. The history also includes 16 critical and 92 high-severity records.

The latest records materially affect how this history should be read. The dataset identifies a critical remote-code-execution record affecting the 6.9 and 7.0 branches before 6.9.5 and 7.0.2, together with a high-severity SQL-injection record affecting several maintained branches. This demonstrates why WordPress Core maintenance should follow the supported release branch and security releases, not simply a fixed calendar schedule.

Of the 369 associated records, 367 are marked patched and two are currently marked unpatched in the synchronized source. Those counts describe source records; they do not establish that a particular website is exposed or compromised.

Practical Next Steps

  1. Identify the exact Core release. Record the installed WordPress version and whether the site is following the current major branch or an older supported branch.
  2. Compare it with the affected ranges. Recent source records list patched values including 7.0.2, 6.9.5 and 6.8.6. Use the branch-specific value shown for each record rather than treating one version number as universal.
  3. Apply security releases with a tested recovery path. Take a verified backup, update Core, clear application and edge caches, then test login, publishing, REST API and scheduled tasks.
  4. Review exposure separately from patching. If the site ran an affected release while a high-impact issue was public, review administrator accounts, file changes, request logs and unexpected scheduled activity. An affected version alone does not prove exploitation.
  5. Keep automatic minor security updates observable. Confirm that update notifications, failure reporting and backups are functioning so a failed automatic update does not remain unnoticed.

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory