WordPress
Core and plugin vulnerabilities in the most widely deployed CMS on the web.
Published work on this topic
| 2026-08-17 | CVE-2026-19598 | CVE-2026-19598: Pods Auth Bypass - Privilege Escalation | PoC | |
| 2026-08-17 | CVE-2026-28185 | CVE-2026-28185: Login with Google Auth Bypass | PoC | |
| 2026-08-13 | CVE-2026-18391 | CVE-2026-18391: WooCommerce Subscriptions - RCE | PoC | |
| 2026-08-10 | CVE-2026-13001 | CVE-2026-13001: Podlove Podcast Publisher RCE | PoC | |
| 2026-08-08 | CVE-2026-14364 | CVE-2026-14364: TrueBooker Auth Bypass | PoC | |
| 2026-08-07 | CVE-2026-64638 | CVE-2026-64638: WordPress XSS2Shell Pre-Auth RCE | PoC | |
| 2026-07-24 | CVE-2026-63030 | CVE-2026-63030: WordPress wp2shell Pre-Auth RCE | PoC |
