Software intelligence
Important: Wordpress appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
378
Latest advisory
12 August 2026
CISA KEV matches
2
In this WordPress feed
WordPress slug
wordpress
WordPress core
This catalog lists 378 known advisories affecting Wordpress. The most recent was published on 12 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. 2 advisories are cross-referenced with the CISA Known Exploited Vulnerabilities catalog — prioritise patching those first. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload
May allow attackers to run arbitrary code on the server if exploited.
Published 12 August 2026
WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Quick Edit
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 8 August 2026
WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Site Creation on Multisite
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 8 August 2026
Known Wordpress advisories published by month.
No CVE assigned · Published 10 March 2026
Affected versions: ≥ 6.8 and ≤ 6.8.3; ≥ 6.9 and ≤ 6.9.1
No CVE assigned · Published 10 March 2026
Affected versions: ≥ 6.8 and ≤ 6.8.3; ≥ 6.9 and ≤ 6.9.1
CVE-2025-58674 · Published 22 September 2025
Affected versions: ≤ 4.7; ≥ 6.1 and ≤ 6.1.8…
CVE-2025-58246 · Published 22 September 2025
Affected versions: ≥ 6.1 and ≤ 6.1.8; ≥ 6.2 and ≤ 6.2.7…
CVE-2024-32111 · Published 24 June 2024
Affected versions: < 4.1; ≥ 5.8 and ≤ 5.8.9…
CVE-2024-6307 · Published 24 June 2024
Affected versions: ≥ 5.9 and ≤ 5.9.9; ≥ 6.0 and ≤ 6.0.8…
CVE-2024-31111 · Published 24 June 2024
Affected versions: ≥ 5.9 and ≤ 5.9.9; ≥ 6.0 and ≤ 6.0.8…
CVE-2024-4439 · Published 9 April 2024
Affected versions: ≥ 6.0 and ≤ 6.0.7; ≥ 6.1 and ≤ 6.1.5…
CVE-2023-5692 · Published 4 April 2024
Affected versions: ≤ 6.4.3
CVE-2024-31211 · Published 6 December 2023
Affected versions: ≥ 6.4.0 and ≤ 6.4.0; ≥ 6.4.1 and ≤ 6.4.1
No CVE assigned · Published 12 October 2023
Affected versions: ≤ 4.1.38; ≥ 5.7 and ≤ 5.7.9…
No CVE assigned · Published 12 October 2023
Affected versions: ≥ 5.7 and ≤ 5.7.9; ≥ 5.8 and ≤ 5.8.7…
CVE-2023-38000 · Published 12 October 2023
Affected versions: ≥ 5.9 and ≤ 5.9.7; ≥ 6.0 and ≤ 6.0.5…
CVE-2023-5561 · Published 12 October 2023
Affected versions: ≥ 5.7 and ≤ 5.7.9; ≥ 5.8 and ≤ 5.8.7…
CVE-2023-39999 · Published 12 October 2023
Affected versions: ≤ 4.1.38; ≥ 5.7 and ≤ 5.7.9…
SiteRespond Defence matches your installed Wordpress version against this catalog when the Defence plugin is connected to your WordPress site.