WordPress 4.7.32

WordPress 4.7.32 has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2026; all 16 are fixed as of August 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2026 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (19%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Insufficient Verification Of Data Authenticity.

Every one of the 16 issues recorded for WordPress 4.7.32 has a vendor fix available, so running the current release closes all known holes.

13 independent researchers contributed these findings, one record each.

01234567891020.06.2012Today20.06.20123.7WordPress Core - Informational < 6.8 - Weak Hashing Algorithm CVSS 3.7 · 20.06.201203.05.20175.9Wordpress Core < 5.5 - Unauthorized Password Reset via Interception CVSS 5.9 · 03.05.201705.02.20187.5WordPress Core < 5.0 - Denial of Service CVSS 7.5 · 05.02.201816.08.20188.8WordPress Core < 4.9 - Insecure Deserialization CVSS 8.8 · 16.08.201819.02.20196.5WordPress Core <= 5.0.3 - Path Traversal and Local File Inclusion CVSS 6.5 · 19.02.201910.11.20215.3WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3 CVSS 5.3 · 10.11.202125.11.20218.1WordPress Core < 5.8 - Dependency Confusion CVSS 8.1 · 25.11.202104.04.20245.3WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink CVSS 5.3 · 04.04.202408.08.20265.3WordPress Core <= 7.0.2 - Unauthenticated Sensitive Information Exposure via Comment Feeds CVSS 5.3 · 08.08.20265.8WordPress Core <= 7.0.2 - Unauthenticated Blind Server-Side Request Forgery CVSS 5.8 · 08.08.20265.5WordPress Core <= 7.0.2 - Authenticated (Author+) CSS Injection CVSS 5.5 · 08.08.20264.3WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Email Change Confirmation Bypass CVSS 4.3 · 08.08.20264.9WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Quick Edit CVSS 4.9 · 08.08.20264.3WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Site Creation on Multisite CVSS 4.3 · 08.08.20266.1WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter CVSS 6.1 · 08.08.20266.4WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Emoji Settings Element CVSS 6.4 · 08.08.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

16

Get automatic notifications for all WordPress 4.7.32 vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2017-1000600

WordPress Core < 4.9 - Insecure Deserialization

Read the full analysis

Vulnerability Records

16 records
2026-08-08 00:00N/A
5.3
Medium
Elio Gubser (odkdn1)Yes
2026-08-08 00:00N/A
5.8
Medium
Andrew MacPhersonYes
2026-08-08 00:00N/A
5.5
Medium
AnonymousYes
2026-08-08 00:00N/A
4.3
Medium
0waysYes
2026-08-08 00:00N/A
4.9
Medium
moochiYes
2026-08-08 00:00N/A
4.3
Medium
Aikido SecurityYes
2026-08-08 00:00CVE-2026-64638
6.1
Medium
pwn.ai TeamYes
2026-08-08 00:00N/A
6.4
Medium
Asaf MozesYes
2024-04-04 00:00CVE-2023-5692
5.3
Medium
Francesco CarlucciYes
2021-11-25 00:00CVE-2021-44223
8.1
High
Kamil VavraYes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C