SecAlerts
W

WordPress

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 6, 2025 to present

1000
Total CVEs
547
Critical+High
6
Exploited
546
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
546
Critical/High
Risk Level
49/100
medium
⚠️ 6 Active Exploits 1 Zero-Days🆕 41Fresh (<7d)📈 238 in Last 30 Days

Severity Distribution

Critical
85
High
462
Medium
426
Low
10

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
94

Age Distribution

Common Weaknesses (CWE)

1
XSS
246
2
SQL Injection
76
3
CSRF
45
4
Path Traversal
29
5
Infoleak
21

Most Affected Products

1. WordPress WordPress21
2. WordPress AI Engine6
3. WordPress Contest Gallery6
4. WordPress Togo theme5
5. WordPress WP Photo Album Plus4

Recent Vulnerabilities

See more →
CVE-2026-17608
CVSS 6.5medium

WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion

8/16/2026🔧 No Patch
CVE-2026-19711
unknown

Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request

8/16/2026🔧 No Patch
CVE-2026-13712
unknown

Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

8/16/2026🔧 No Patch
CVE-2026-17582
CVSS 4.9medium

Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate)

8/16/2026🔧 No Patch
CVE-2026-16758
CVSS 6.4medium

Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

8/16/2026🔧 No Patch
CVE-2026-15790
CVSS 6.4medium

Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode

8/16/2026🔧 No Patch
CVE-2026-15009
CVSS 6.1medium

Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter

8/16/2026🔧 No Patch
CVE-2026-15441
CVSS 5.3medium

Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter

8/16/2026🔧 No Patch
CVE-2026-2487
CVSS 4.4medium

Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting

8/16/2026🔧 No Patch
CVE-2026-18855
CVSS 9.1critical

Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter

8/15/2026🔧 No Patch

Monitor WordPress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

WordPress Security Vulnerabilities & Risk Score | 1000 CVEs | SecAlerts - SecAlerts