Skip to content
Noroxi

wpengine records

13 published records for vendor wpengine.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
46.2%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

13 records
  • Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection

    HighCVSS 8.8Proof of conceptEPSS 68%

    wpengine · better search replaceFeb 5, 2024

  • The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratio

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    wpengine · wpgraphqlJun 10, 2019

  • An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.

    CriticalCVSS 9.1Proof of conceptEPSS 35%

    wpengine · wpgraphqlJun 10, 2019

  • WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability

    CriticalCVSS 10.0No exploitEPSS 1%

    wpengine, inc. · wp migrateMar 28, 2024

  • Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability

    CriticalCVSS 9.9No exploitEPSS 1%

    wpengine inc · advanced custom fields proJun 10, 2024

  • WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpengine · php compatibility checkerJul 11, 2023

  • CVE-2019-9881
    27Monitor

    The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even wh

    MediumCVSS 5.3Proof of conceptEPSS 19%

    wpengine · wpgraphqlJun 10, 2019

  • CVE-2024-2761
    27Monitor

    Genesis Blocks < 3.1.3 - Contributor+ Stored XSS

    MediumCVSS 6.8No exploitEPSS 1%

    wpengine · genesis blocksApr 19, 2024

  • CVE-2024-3901
    27Monitor

    Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS

    MediumCVSS 6.8No exploitEPSS 1%

    wpengine · genesis blocksMay 15, 2025

  • WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)

    MediumCVSS 6.5No exploitEPSS 0%

    wpengine · wpgraphqlNov 12, 2023

  • Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5

    MediumCVSS 6.1No exploitEPSS 0%

    wpengine · advanced custom fieldsSep 4, 2024

  • CVE-2022-1563
    21Monitor

    WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure

    MediumCVSS 5.3No exploitEPSS 1%

    wpengine · wpgraphqlJan 16, 2024

  • CVE-2024-3563
    21Monitor

    Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes

    MediumCVSS 5.4No exploitEPSS 0%

    wpengine · genesis blocksJul 9, 2024