Записи wpengine
13 опубликованных записей вендора wpengine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 46,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-306 Missing Authentication for Critical Function3
- CWE-502 Deserialization of Untrusted Data2
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-284 Improper Access Control1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
- WP Engine Bug BountyIntigriti · с вознаграждением · до 2 500 $
- WP Engine VDPIntigriti · только раскрытие (VDP)
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2023-6933Proof of concept | Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injectionwpengine · better search replace · CWE-502 | Высокая8,8 | — | 68,0 % | 5 февр. 2024 г. |
53В плане | CVE-2019-9879Proof of concept | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratiowpengine · wpgraphql · CWE-306 | Критическая9,8 | — | 46,6 % | 10 июн. 2019 г. |
46В плане | CVE-2019-9880Proof of concept | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.wpengine · wpgraphql · CWE-306 | Критическая9,1 | — | 34,8 % | 10 июн. 2019 г. |
40В плане | CVE-2024-30225Эксплойта нет | WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerabilitywpengine, inc. · wp migrate · CWE-502 | Критическая10,0 | — | 0,7 % | 28 мар. 2024 г. |
39Наблюдать | CVE-2024-34762Эксплойта нет | Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerabilitywpengine inc · advanced custom fields pro · CWE-22 | Критическая9,9 | — | 0,6 % | 10 июн. 2024 г. |
35Наблюдать | CVE-2023-24421Эксплойта нет | WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)wpengine · php compatibility checker · CWE-352 | Высокая8,8 | — | 0,3 % | 11 июл. 2023 г. |
27Наблюдать | CVE-2019-9881Proof of concept | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even whwpengine · wpgraphql · CWE-306 | Средняя5,3 | — | 18,8 % | 10 июн. 2019 г. |
27Наблюдать | CVE-2024-2761Эксплойта нет | Genesis Blocks < 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Средняя6,8 | — | 0,7 % | 19 апр. 2024 г. |
27Наблюдать | CVE-2024-3901Эксплойта нет | Genesis Blocks <= 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Средняя6,8 | — | 0,6 % | 15 мая 2025 г. |
26Наблюдать | CVE-2023-23684Эксплойта нет | WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)wpengine · wpgraphql · CWE-918 | Средняя6,5 | — | 0,5 % | 12 нояб. 2023 г. |
24Наблюдать | CVE-2024-45429Эксплойта нет | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5wpengine · advanced custom fields · CWE-79 | Средняя6,1 | — | 0,4 % | 4 сент. 2024 г. |
21Наблюдать | CVE-2022-1563Эксплойта нет | WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosurewpengine · wpgraphql · CWE-284 | Средняя5,3 | — | 0,7 % | 16 янв. 2024 г. |
21Наблюдать | CVE-2024-3563Эксплойта нет | Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributeswpengine · genesis blocks · CWE-79 | Средняя5,4 | — | 0,3 % | 9 июл. 2024 г. |
- CVE-2023-693355В плане
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
ВысокаяCVSS 8,8Proof of conceptEPSS 68 %wpengine · better search replace5 февр. 2024 г.
- CVE-2019-987953В плане
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratio
КритическаяCVSS 9,8Proof of conceptEPSS 47 %wpengine · wpgraphql10 июн. 2019 г.
- CVE-2019-988046В плане
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.
КритическаяCVSS 9,1Proof of conceptEPSS 35 %wpengine · wpgraphql10 июн. 2019 г.
- CVE-2024-3022540В плане
WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %wpengine, inc. · wp migrate28 мар. 2024 г.
- CVE-2024-3476239Наблюдать
Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %wpengine inc · advanced custom fields pro10 июн. 2024 г.
- CVE-2023-2442135Наблюдать
WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpengine · php compatibility checker11 июл. 2023 г.
- CVE-2019-988127Наблюдать
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even wh
СредняяCVSS 5,3Proof of conceptEPSS 19 %wpengine · wpgraphql10 июн. 2019 г.
- CVE-2024-276127Наблюдать
Genesis Blocks < 3.1.3 - Contributor+ Stored XSS
СредняяCVSS 6,8Эксплойта нетEPSS 1 %wpengine · genesis blocks19 апр. 2024 г.
- CVE-2024-390127Наблюдать
Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS
СредняяCVSS 6,8Эксплойта нетEPSS 1 %wpengine · genesis blocks15 мая 2025 г.
- CVE-2023-2368426Наблюдать
WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wpengine · wpgraphql12 нояб. 2023 г.
- CVE-2024-4542924Наблюдать
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpengine · advanced custom fields4 сент. 2024 г.
- CVE-2022-156321Наблюдать
WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wpengine · wpgraphql16 янв. 2024 г.
- CVE-2024-356321Наблюдать
Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wpengine · genesis blocks9 июл. 2024 г.