Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
WordPress Number Of NVD 349 CRITICAL 17 HIGH 79 MEDIUM 235 LOW 18
URL https://wordpress.org/
Explanation It is an open source blogging software written in PHP.
It can be used not only for blogs, but also for personal and corporate web sites, and offers a large number of additional features and good-looking themes.
It may be the most used Content Management System (CMS) in the world.

There are many plugins, and if you have enough knowledge, you can build a site that can be used for commercial purposes.
However, since there are some vulnerabilities caused by plugins, you need to carefully select the right plugin to use.

Since security updates are not made for other than the latest version, it is officially announced that older versions cannot be used safely.
In some cases, security issues are fixed for older versions.
Since there are many plugins (additional functions) available for WordPress, you need to check each plugin for vulnerabilities and new versions.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://ja.wordpress.org/download/
2 https://github.com/wordpress/wordpress
3 https://wordpress.org/download/releases/
4 https://ja.wordpress.org/download/releases/
5 https://ja.wordpress.org/about/history/
6 https://wordpress.org/news/category/releases/
7 https://ja.wordpress.org/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
231 wordpress 6 6.8.3 Sept. 30, 2025 Nov. 2, 2022 0 0 10 0
232 wordpress 5.9 5.9.5 Oct. 17, 2022 Jan. 25, 2022 0 0 10 0
233 wordpress 5.8 5.8.1 Sept. 9, 2021 July 21, 2021 0 3 13 0
234 wordpress 5.7 5.7.3 Sept. 9, 2021 March 10, 2021 2 4 14 0
235 WordPress 5.6 5.6.5 Sept. 9, 2021 Dec. 8, 2020 2 4 14 0
236 WordPress 5.5 5.5.6 Sept. 9, 2021 Aug. 11, 2020 7 5 16 0
237 WordPress 5.4 5.4.7 Sept. 9, 2021 April 28, 2020 7 7 24 2
238 WordPress 5.3 5.3.9 Sept. 11, 2021 Nov. 21, 2019 8 7 27 2
239 WordPress 5.2 5.2.12 Sept. 9, 2021 May 19, 2019 10 9 38 2
240 WordPress 5.1 5.1.11 Sept. 22, 2021 March 11, 2019 10 10 37 2
241 WordPress 5.0 5.0.14 Sept. 22, 2021 Dec. 10, 2018 11 12 43 2
242 WordPress 4.9 4.9.18 May 12, 2021 Nov. 17, 2017 11 17 49 2
243 WordPress 4.8 4.8.17 May 12, 2021 June 23, 2017 13 20 57 2
244 WordPress 4.7 4.7.18 June 11, 2020 Dec. 7, 2016 16 28 72 2
245 WordPress 4.6 4.6.19 June 11, 2020 Aug. 17, 2016 16 26 70 2
246 WordPress 4.5 4.5.22 June 11, 2020 April 14, 2016 16 33 76 2
247 WordPress 4.4 4.4.23 June 11, 2020 Dec. 9, 2015 16 36 78 2
248 WordPress 4.3 4.3.24 June 11, 2020 Aug. 19, 2015 16 36 81 2
249 WordPress 4.2 4.2.28 June 11, 2020 April 28, 2015 16 37 89 3
250 WordPress 4.1 4.1.31 June 11, 2020 Dec. 19, 2014 16 37 91 3
251 wordpress 4.0 4.0.38 Dec. 15, 2014 Dec. 15, 2014 16 37 97 3
252 WordPress 3.9 3.9.40 Nov. 30, 2022 April 17, 2014 16 38 102 4
253 WordPress 3.8 3.8.41 Nov. 30, 2022 Dec. 16, 2013 16 37 102 4
254 WordPress 3.7 3.7.5 Nov. 30, 2022 Oct. 25, 2013 16 37 102 4
255 wordpress 3.6 3.6.1 Sept. 11, 2013 Aug. 1, 2013 Jan. 1, 2000 15 37 94 4
256 wordpress 3.5 3.5.2 June 21, 2013 Nov. 11, 2012 Jan. 1, 2000 15 37 105 4
257 wordpress 3.4 3.4.2 Sept. 6, 2012 June 13, 2012 Jan. 1, 2000 15 37 108 7
258 wordpress 3.3 3.3.3 June 27, 2012 Dec. 12, 2011 Jan. 1, 2000 15 40 119 6
259 wordpress 3.2 3.2.1 July 12, 2011 July 4, 2011 Jan. 1, 2000 15 44 122 5
260 wordpress 3.1 3.1.4 June 29, 2011 Feb. 23, 2011 Jan. 1, 2000 15 44 125 5
261 wordpress 3.0 3.0.6 April 26, 2011 June 17, 2010 Jan. 1, 2000 15 40 132 7
262 wordpress 2.9 2.9.2 Feb. 15, 2010 Dec. 18, 2009 Jan. 1, 2000 15 39 133 7
263 wordpress 2.8 2.8.6 Nov. 12, 2009 June 11, 2009 Jan. 1, 2000 15 41 137 8
264 wordpress 2.7 2.7.1 Feb. 10, 2009 Dec. 10, 2008 Jan. 1, 2000 15 41 140 8
265 wordpress 2.6 2.6.5 Nov. 25, 2008 July 15, 2008 Jan. 1, 2000 15 44 143 8
266 wordpress 2.5 2.5.1 April 25, 2008 March 29, 2008 Jan. 1, 2000 15 46 143 8
267 wordpress 2.3 2.3.3 Feb. 5, 2008 Sept. 25, 2007 Jan. 1, 2000 16 46 147 9
268 wordpress 2.2 2.2.3 Sept. 24, 2007 Sept. 24, 2007 Jan. 1, 2000 16 48 158 9
269 wordpress 2.1 2.1.3 Sept. 24, 2007 Sept. 24, 2007 Jan. 1, 2000 16 51 157 9
270 wordpress 2.0 2.0.9 Sept. 24, 2007 Sept. 24, 2007 Jan. 1, 2000 16 55 180 9
271 wordpress 1.5 1.5.2 Sept. 24, 2007 Sept. 24, 2007 Jan. 1, 2000 16 58 173 8
272 wordpress 1.2 1.2.5 Sept. 24, 2007 Sept. 24, 2007 Jan. 1, 2000 15 55 175 8
273 wordpress 1.6 1.6.2 Jan. 1, 2000 16 49 161 8
274 wordpress 1.3 1.3.3 Jan. 1, 2000 15 49 164 8
275 wordpress 1.1 1.1.1 Jan. 1, 2000 15 49 163 8
276 wordpress 1.0 1.0.2 Sept. 24, 2007 Jan. 1, 2000 15 53 169 8
277 wordpress 0.72 0.72 Jan. 1, 2000 15 51 163 8
278 wordpress 0.711 0.711 Jan. 1, 2000 15 51 163 8
279 wordpress 0.71 0.71 Sept. 24, 2007 Jan. 1, 2000 15 53 167 8
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
231 -
10.0
HIGH Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote … NVD-CWE-noinfo
CVE-2012-2399 cpe:2.3:a:wordpress:wordpress:3.3:*
cpe:2.3:a:wordpress:wordpress:3.1:*
cpe:2.3:a:wordpress:wordpress:3.1.3:*
3.3.1 2024-11-21 10:39
2012-04-22
Show GitHub Exploit DB Packet Storm
232 -
5.0
MEDIUM wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attacker… NVD-CWE-noinfo
CVE-2012-0937 cpe:2.3:a:wordpress:wordpress:3.3:*
cpe:2.3:a:wordpress:wordpress:3.2.1:*
cpe:2.3:a:wordpress:wordpress:3.1:*
3.3.1 2024-11-21 10:36
2012-01-31
Show GitHub Exploit DB Packet Storm
233 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or … CWE-79
Cross-site Scripting
CVE-2012-0782 cpe:2.3:a:wordpress:wordpress:3.3:*
cpe:2.3:a:wordpress:wordpress:3.2.1:*
cpe:2.3:a:wordpress:wordpress:3.1:*
3.3.1 2024-11-21 10:35
2012-01-31
Show GitHub Exploit DB Packet Storm
234 -
7.5
HIGH wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to confi… NVD-CWE-noinfo
CVE-2011-4899 cpe:2.3:a:wordpress:wordpress:3.3:*
cpe:2.3:a:wordpress:wordpress:3.2.1:*
cpe:2.3:a:wordpress:wordpress:3.1:*
3.3.1 2024-11-21 10:33
2012-01-31
Show GitHub Exploit DB Packet Storm
235 -
5.0
MEDIUM wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL creden… CWE-200
Information Exposure
CVE-2011-4898 cpe:2.3:a:wordpress:wordpress:3.3:*
cpe:2.3:a:wordpress:wordpress:3.2.1:*
cpe:2.3:a:wordpress:wordpress:3.1:*
3.3.1 2024-11-21 10:33
2012-01-31
Show GitHub Exploit DB Packet Storm
236 -
2.6
LOW Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via th… CWE-79
Cross-site Scripting
CVE-2012-0287 cpe:2.3:a:wordpress:wordpress:3.3:* 2024-11-21 10:34
2012-01-6
Show GitHub Exploit DB Packet Storm
237 -
5.0
MEDIUM WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-a… CWE-200
Information Exposure
CVE-2011-3818 cpe:2.3:a:wordpress:wordpress:3.0.4:*
cpe:2.3:a:wordpress:wordpress:2.9.2:*
2024-11-21 10:31
2011-09-24
Show GitHub Exploit DB Packet Storm
238 -
7.5
HIGH wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection. CWE-89
NVD-CWE-noinfo
SQL Injection
CVE-2011-3130 cpe:2.3:a:wordpress:wordpress:3.2:beta1
cpe:2.3:a:wordpress:wordpress:3.1:*
cpe:2.3:a:wordpress:wordpress:3.1.2:*…
2024-11-21 10:29
2011-08-11
Show GitHub Exploit DB Packet Storm
239 -
9.3
HIGH The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-3129 cpe:2.3:a:wordpress:wordpress:3.2:beta1
cpe:2.3:a:wordpress:wordpress:3.1:*
cpe:2.3:a:wordpress:wordpress:3.1.2:*…
2024-11-21 10:29
2011-08-11
Show GitHub Exploit DB Packet Storm
240 -
5.0
MEDIUM WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php. CWE-200
Information Exposure
CVE-2011-3128 cpe:2.3:a:wordpress:wordpress:3.2:beta1
cpe:2.3:a:wordpress:wordpress:3.1:*
cpe:2.3:a:wordpress:wordpress:3.1.2:*…
2024-11-21 10:29
2011-08-11
Show GitHub Exploit DB Packet Storm