SecAlerts
W

WordPress

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 5, 2026 to present

1000
Total CVEs
555
Critical+High
6
Exploited
555
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
555
Critical/High
Risk Level
48/100
medium
⚠️ 6 Active Exploits⚡ 1 Zero-Days🆕 74Fresh (<7d)📈 236 in Last 30 Days

Severity Distribution

Critical
109
High
446
Medium
408
Low
25

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
117

Age Distribution

Common Weaknesses (CWE)

1
XSS
275
2
SQL Injection
106
3
Path Traversal
31
4
Infoleak
31
5
CSRF
29

Most Affected Products

1. WordPress WordPress48
2. WordPress WP Photo Album Plus7
3. WordPress AI Engine7
4. WordPress Newsletters6
5. WordPress Kirki5

Recent Vulnerabilities

See more →
CVE-2026-96267
CVSS 7.5high

WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter

Oct 3, 2026🔧 No Patch
CVE-2026-101928
CVSS 7.2high

Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author

Oct 3, 2026🔧 No Patch
CVE-2026-97341
CVSS 7.2EPSS 0%high

Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header

Oct 3, 2026🔧 No Patch
CVE-2026-11399
CVSS 4.3medium

Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter

Oct 3, 2026🔧 No Patch
CVE-2026-95817
CVSS 7.2high

DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content

Oct 2, 2026🔧 No Patch
CVE-2026-103068
CVSS 8.8high

WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-102378
CVSS 7.1high

WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-100514
CVSS 7.5high

WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-97281
CVSS 6.3EPSS 0%medium

WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-97277
CVSS 7.6EPSS 0%high

WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability

Oct 1, 2026🔧 No Patch

Monitor WordPress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

WordPress Security Vulnerabilities & Risk Score | 1000 CVEs | SecAlerts - SecAlerts