CyberMax
Home › Exploited CVEs

WordPress known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 6 WordPress CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-25), and 0 are known to be used in ransomware campaigns.

WordPress CVEs added to CISA KEV per year
2021: 3202132026: 320263

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected WordPress products

Core (3), File Manager Plugin (1), Snap Creek Duplicator Plugin (1), Social Warfare Plugin (1).

All WordPress CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-87902CoreCore Remote File Inclusion2026-09-252026-09-2818.2%–
CVE-2026-63030CoreCore Interpretation Conflict2026-07-212026-07-2410.1%–
CVE-2026-60137CoreCore SQL Injection2026-07-212026-08-045.9%–
CVE-2020-25213File Manager PluginFile Manager Plugin Remote Code Execution2021-11-032022-05-0397.3%–
CVE-2020-11738Snap Creek Duplicator PluginSnap Creek Duplicator Plugin File Download2021-11-032022-05-0397.8%–
CVE-2019-9978Social Warfare PluginSocial Warfare Plugin Cross-Site Scripting (XSS)2021-11-032022-05-0372.9%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors