<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/wordpress.xml</id>
  <title>Exploit Radar: exploited WordPress vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for WordPress products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/wordpress.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/wordpress/"/>
  <updated>2026-09-25T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-87902/</id>
    <title>CVE-2026-87902 — WordPress Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-87902/"/>
    <updated>2026-09-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from WordPress; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-63030/</id>
    <title>CVE-2026-63030 — WordPress Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-63030/"/>
    <updated>2026-07-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from WordPress; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-60137/</id>
    <title>CVE-2026-60137 — WordPress Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-60137/"/>
    <updated>2026-07-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from WordPress; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on July 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-25213/</id>
    <title>CVE-2020-25213 — WordPress Plugins</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-25213/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from WordPress. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-11738/</id>
    <title>CVE-2020-11738 — WordPress Plugins</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-11738/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from WordPress. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-9978/</id>
    <title>CVE-2019-9978 — WordPress Plugins</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-9978/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from WordPress. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
