WordPress known exploited vulnerabilities
CISA lists 6 WordPress CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-25), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-11738 (Snap Creek Duplicator Plugin): EPSS 97.8%, added 2021-11-03
- CVE-2020-25213 (File Manager Plugin): EPSS 97.3%, added 2021-11-03
- CVE-2019-9978 (Social Warfare Plugin): EPSS 72.9%, added 2021-11-03
- CVE-2026-87902 (Core): EPSS 18.2%, added 2026-09-25
- CVE-2026-63030 (Core): EPSS 10.1%, added 2026-07-21
Most affected WordPress products
Core (3), File Manager Plugin (1), Snap Creek Duplicator Plugin (1), Social Warfare Plugin (1).
All WordPress CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-87902 | Core | Core Remote File Inclusion | 2026-09-25 | 2026-09-28 | 18.2% | – |
| CVE-2026-63030 | Core | Core Interpretation Conflict | 2026-07-21 | 2026-07-24 | 10.1% | – |
| CVE-2026-60137 | Core | Core SQL Injection | 2026-07-21 | 2026-08-04 | 5.9% | – |
| CVE-2020-25213 | File Manager Plugin | File Manager Plugin Remote Code Execution | 2021-11-03 | 2022-05-03 | 97.3% | – |
| CVE-2020-11738 | Snap Creek Duplicator Plugin | Snap Creek Duplicator Plugin File Download | 2021-11-03 | 2022-05-03 | 97.8% | – |
| CVE-2019-9978 | Social Warfare Plugin | Social Warfare Plugin Cross-Site Scripting (XSS) | 2021-11-03 | 2022-05-03 | 72.9% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors