Critical WordPress Flaw Rated 9.2/10 Has Persisted Since 2016
Security researchers have identified a high-severity vulnerability in WordPress that carries a CVSS score of 9.2 out of 10, indicating it can be exploited with relatively low complexity and minimal attacker privileges. The flaw has reportedly existed in every version of the platform released since 2016, meaning it has gone undetected or unpatched for nearly a decade.
GoKawiil's interpretation of the reporting above, not reported fact.
WordPress powers a substantial share of websites globally, so a long-standing critical vulnerability of this severity could expose millions of sites to potential compromise, data theft, or takeover. The scoring system used (CVSS) accounts for factors like attack vector, complexity, and required privileges, and a 9.2 rating signals that exploitation is both feasible and highly impactful, making rapid patching essential once a fix is available.
- The vulnerability scores 9.2/10 on the CVSS severity scale, placing it in the critical range.
- It has reportedly affected every WordPress version since 2016, suggesting a long window of exposure.
- Given WordPress's massive market share, unpatched sites could face significant security risks until remediation is applied.
Source: github.com, 2026-09-22
Published there as: “A WordPress vulnerability scored 9.2/10 is present in all versions since 2016”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.