232 exploited vulnerabilities in Wordpress
- Vendors
- Bitnami, Unknown, WordPress, Alt Linux, Linux Mint, Php
- With known exploits
- 232
- Affected Meowapps Ai Engine versions
- < 1.9.99
- Affected Phpmailer Project Phpmailer versions
- < 5.2.18
- Affected Wordpress versions
- = 0.71, 0.72, 0.711, 1.0, 1.0.1, 1.2, 1.2.1, 1.2.2, 1.5, 1.5.1, 1.5.1.3, 1.5.2, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.9, 2.0.10, 2.0.11, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.3, 2.3.1, 2.3.2, 2.5, 2.5.1, 2.6, 2.6.1, 2.6.2, 2.6.3, 6.9.5, 7.0.2, 6.4.2, 5.8, 5.5.2, 4.9.9, 5.0.1, 4.8.1, 6.8.6, 5.1.1, 2.3.3, 0.6.2, 0.6.2.1, 0.7, 0.71-gold, 1.0-platinum, 1.0.1-miles, 1.0.2, 1.0.2-blakey, 1.2-delta, 1.2-mingus, 1.3.1, 1.4, 1.5-strayhorn, 1.5.1.1, 1.5.1.2, 1.6, 2.0.8, 4.1.40, 4.2.37, 4.3.33, 4.4.32, 4.5.31, 4.6.28, 4.7.28, 4.8.24, 4.9.25, 5.0.21, 5.1.18, 5.2.20, 5.3.17, 5.4.15, 5.5.14, 5.6.13, 5.7.11, 5.8.9, 5.9.9, 6.0.7, 6.1.5, 6.2.4, 6.3.3, 6.4.3, 5.0, 4.9.7, 4.7.4, 4.4.1
- Affected Valvepress Automatic versions
- โค 3.92.0
- Affected Goodlayers Good Learning Management System versions
- โค 2.1.4
- Affected Calmar-webmedia Total Donations versions
- โค 2.0.5
- Affected Wp-pdf Pdf Embedder versions
- = 4.4
- Affected Tribulant Slideshow Gallery versions
- = 1.6.8
Vulnerabilities with exploits
Highest CVSS first โ 26 of these already have exploit code on Sploitus
CVE-2025-41240
CVE-2023-51409 4 exploits
๐ WordPress AI Engine: ChatGPT Chatbot 1.9.98 Shell Upload๐ WordPress AI Engine 3.0.0 Shell Upload
CVE-2016-10033 58 exploits
Exploit for Argument Injection in Phpmailer_Project PhpmailerExploit for Argument Injection in Phpmailer_Project Phpmailer
CVE-2009-2853 2 exploits
CVE-2008-6767
CVE-2024-27956 16 exploits
CVE-2026-63030 60 exploits
CVE-2024-31211 1 exploit
CVE-2021-44223
CVE-2020-27481 1 exploit
CVE-2020-28032 1 exploit
CVE-2019-6703
CVE-2019-19589
CVE-2018-18018
CVE-2018-3810 4 exploits
WordPress Smart Google Code Inserter Plugin < 3.5 - Authentication Bypass / SQL InjectionWordPress Plugin Smart Google Code Inserter 3.5 - Authentication Bypass SQL Injection
CVE-2018-20148
CVE-2017-14723
CVE-2017-1002002 3 exploits
CVE-2017-1002000 3 exploits
CVE-2007-6013
CVE-2026-60137 44 exploits
CVE-2019-10673 2 exploits
WordPress Ultimate Member 2.0.38 Cross Site Request Forgery VulnerabilityWordPress Ultimate Member 2.0.38 Cross Site Request Forgery
CVE-2019-9787 3 exploits
Exploit for Cross-Site Request Forgery (CSRF) in WordpressExploit for Cross-Site Request Forgery (CSRF) in Wordpress
CVE-2008-4769 1 exploit
CVE-2026-5144
CVE-2024-31210
CVE-2020-8658 1 exploit
CVE-2020-28339
CVE-2019-8942 8 exploits
Exploit for Unrestricted Upload of File with Dangerous Type in WordpressExploit for Unrestricted Upload of File with Dangerous Type in Wordpress
CVE-2019-1000003 1 exploit
CVE-2016-10945
CVE-2018-5656
CVE-2018-12895 3 exploits
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) ExploitWordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
CVE-2017-9064
CVE-2026-28507
CVE-2017-9062
CVE-2016-2222
CVE-2020-11027 3 exploits
WordPress Theme Medic 1.0.0 Weak Password Recovery MechanismWordPress Medic Theme v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password Exploit
CVE-2008-5695 1 exploit
CVE-2026-4248
CVE-2022-21662
CVE-2022-21661 13 exploits
CVE-2021-42360
CVE-2020-36848 1 exploit
CVE-2020-11497 3 exploits
WordPress NAB Transact WooCommerce 2.1.0 Payment Bypass VulnerabilityWooCommerce - NAB Transact < 2.1.2 - Payment Bypass
CVE-2019-20209 3 exploits
CVE-2018-6389 11 exploits
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_PlatformExploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
CVE-2018-20151
CVE-2017-9065
CVE-2017-1002006