VENDOR
WordPress vulnerabilities: CVEs, exploitation and patches
Every WordPress CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-65640
WordPress PostScript upload remote code execution via upload_filesHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-64638 HIGH 8.9
-
CVE-2026-60137
WordPress Core SQL injection via author__not_in parameterMEDIUM 5.9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-63030
WordPress Core REST API route confusion remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87902
Remote file inclusion via page-template resolution (get_page_template)HIGH 8.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
5 CVEs · page 1 of 1