SecAlerts
WordPress logo

WordPress

Security Risk Profile

51
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 27, 2025 to present

1000
Total CVEs
551
Critical+High
6
Exploited
550
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
550
Critical/High
Risk Level
51/100
medium
⚠️ 6 Active Exploits 1 Zero-Days🆕 50Fresh (<7d)📈 205 in Last 30 Days

Severity Distribution

Critical
75
High
476
Medium
433
Low
6

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
94

Age Distribution

Common Weaknesses (CWE)

1
XSS
264
2
CSRF
62
3
SQL Injection
56
4
Path Traversal
24
5
Malicious File Upload
21

Most Affected Products

1. WordPress WordPress18
2. WordPress Togo theme5
3. 8theme XStore4
4. Uxper Togo4
5. WordPress Kirki3

Recent Vulnerabilities

See more →
CVE-2026-15739
CVSS 6.4medium

Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute

7/24/2026🔧 No Patch
CVE-2026-14603
CVSS 7.5high

WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection

7/24/2026🔧 No Patch
CVE-2026-12877
CVSS 9.1critical

Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter

7/24/2026🔧 No Patch
CVE-2026-12497
CVSS 7.5high

ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection

7/24/2026🔧 No Patch
CVE-2026-11354
CVSS 5.3medium

Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter

7/24/2026🔧 No Patch
CVE-2026-65538
CVSS 5.9medium

WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability

7/23/2026🔧 No Patch
CVE-2026-65536
CVSS 6.5medium

WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability

7/23/2026🔧 No Patch
CVE-2026-65526
CVSS 8.5high

WordPress Visualizer plugin <= 4.0.6 - SQL Injection vulnerability

7/23/2026🔧 No Patch
CVE-2026-65512
CVSS 5.4medium

WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability

7/23/2026🔧 No Patch
CVE-2026-65511
CVSS 7.1high

WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability

7/23/2026🔧 No Patch

Monitor WordPress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.