Vendor

WordPress

As of , 6 WordPress vulnerabilities are on CISA's list of exploited vulnerabilities; 3 were added in 2026. Patch first: CVE-2026-63030.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-63030Interpretation ConflictWordPress CorePatch nowForensic triage required by CISA; Metasploit module0.10
2CVE-2026-87902Remote File InclusionWordPress CorePatch nowForensic triage required by CISA; listed in the last 14 days0.46
3CVE-2020-25213Remote Code ExecutionWordPress File Manager PluginPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
4CVE-2020-11738File DownloadWordPress Snap Creek Duplicator PluginPatch this weekMetasploit module; EPSS 0.980.98
5CVE-2026-60137SQL InjectionWordPress CorePatch this weekMetasploit module0.06
6CVE-2019-9978Cross-Site Scripting (XSS)WordPress Social Warfare PluginPatch this weekEPSS 0.730.73

Products

  • Core3 entries
  • File Manager Plugin1 entry
  • Snap Creek Duplicator Plugin1 entry
  • Social Warfare Plugin1 entry

Added each year

1232021: 3320212022: nonenone20222023: nonenone20232024: nonenone20242025: nonenone20252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20213
2022none
2023none
2024none
2025none
20263

Used in ransomware