SecAlerts
WordPress logo

WordPress

Security Risk Profile

50
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 6, 2025 to present

1000
Total CVEs
557
Critical+High
6
Exploited
556
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
556
Critical/High
Risk Level
50/100
medium
⚠️ 6 Active Exploits 1 Zero-Days🆕 44Fresh (<7d)📈 232 in Last 30 Days

Severity Distribution

Critical
84
High
473
Medium
418
Low
10

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
94

Age Distribution

Common Weaknesses (CWE)

1
XSS
242
2
SQL Injection
75
3
CSRF
44
4
Path Traversal
28
5
Malicious File Upload
22

Most Affected Products

1. WordPress WordPress21
2. WordPress AI Engine6
3. WordPress Contest Gallery6
4. WordPress Togo theme5
5. WordPress WP Photo Album Plus4

Recent Vulnerabilities

See more →
CVE-2026-15142
CVSS 7.5high

Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision

8/15/2026🔧 No Patch
CVE-2026-14229
unknown

ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload

8/15/2026🔧 No Patch
CVE-2026-16541
unknown

Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints

8/15/2026🔧 No Patch
CVE-2026-18216
unknown

Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

8/15/2026🔧 No Patch
CVE-2026-16146
CVSS 4.9medium

Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values

8/15/2026🔧 No Patch
CVE-2026-16145
CVSS 7.2high

Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter

8/15/2026🔧 No Patch
CVE-2026-16586
CVSS 6.5medium

Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId'

8/15/2026🔧 No Patch
CVE-2026-15341
CVSS 9.8critical

User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters

8/15/2026🔧 No Patch
CVE-2026-15162
CVSS 7.5high

Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection

8/15/2026🔧 No Patch
CVE-2026-18109
CVSS 7.2high

W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

8/14/2026🔧 No Patch

Monitor WordPress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.