wpengine records
13 published records for vendor wpengine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 46.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-306 Missing Authentication for Critical Function3
- CWE-502 Deserialization of Untrusted Data2
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2023-6933Proof of concept | Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injectionwpengine · better search replace · CWE-502 | High8.8 | — | 68.0% | Feb 5, 2024 |
53Plan | CVE-2019-9879Proof of concept | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratiowpengine · wpgraphql · CWE-306 | Critical9.8 | — | 46.6% | Jun 10, 2019 |
46Plan | CVE-2019-9880Proof of concept | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.wpengine · wpgraphql · CWE-306 | Critical9.1 | — | 34.8% | Jun 10, 2019 |
40Plan | CVE-2024-30225No exploit | WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerabilitywpengine, inc. · wp migrate · CWE-502 | Critical10.0 | — | 0.7% | Mar 28, 2024 |
39Monitor | CVE-2024-34762No exploit | Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerabilitywpengine inc · advanced custom fields pro · CWE-22 | Critical9.9 | — | 0.6% | Jun 10, 2024 |
35Monitor | CVE-2023-24421No exploit | WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)wpengine · php compatibility checker · CWE-352 | High8.8 | — | 0.3% | Jul 11, 2023 |
27Monitor | CVE-2019-9881Proof of concept | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even whwpengine · wpgraphql · CWE-306 | Medium5.3 | — | 18.8% | Jun 10, 2019 |
27Monitor | CVE-2024-2761No exploit | Genesis Blocks < 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Medium6.8 | — | 0.7% | Apr 19, 2024 |
27Monitor | CVE-2024-3901No exploit | Genesis Blocks <= 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Medium6.8 | — | 0.6% | May 15, 2025 |
26Monitor | CVE-2023-23684No exploit | WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)wpengine · wpgraphql · CWE-918 | Medium6.5 | — | 0.5% | Nov 12, 2023 |
24Monitor | CVE-2024-45429No exploit | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5wpengine · advanced custom fields · CWE-79 | Medium6.1 | — | 0.4% | Sep 4, 2024 |
21Monitor | CVE-2022-1563No exploit | WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosurewpengine · wpgraphql · CWE-284 | Medium5.3 | — | 0.7% | Jan 16, 2024 |
21Monitor | CVE-2024-3563No exploit | Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributeswpengine · genesis blocks · CWE-79 | Medium5.4 | — | 0.3% | Jul 9, 2024 |
- CVE-2023-693355Plan
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
HighCVSS 8.8Proof of conceptEPSS 68%wpengine · better search replaceFeb 5, 2024
- CVE-2019-987953Plan
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratio
CriticalCVSS 9.8Proof of conceptEPSS 47%wpengine · wpgraphqlJun 10, 2019
- CVE-2019-988046Plan
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.
CriticalCVSS 9.1Proof of conceptEPSS 35%wpengine · wpgraphqlJun 10, 2019
- CVE-2024-3022540Plan
WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability
CriticalCVSS 10.0No exploitEPSS 1%wpengine, inc. · wp migrateMar 28, 2024
- CVE-2024-3476239Monitor
Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability
CriticalCVSS 9.9No exploitEPSS 1%wpengine inc · advanced custom fields proJun 10, 2024
- CVE-2023-2442135Monitor
WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpengine · php compatibility checkerJul 11, 2023
- CVE-2019-988127Monitor
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even wh
MediumCVSS 5.3Proof of conceptEPSS 19%wpengine · wpgraphqlJun 10, 2019
- CVE-2024-276127Monitor
Genesis Blocks < 3.1.3 - Contributor+ Stored XSS
MediumCVSS 6.8No exploitEPSS 1%wpengine · genesis blocksApr 19, 2024
- CVE-2024-390127Monitor
Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS
MediumCVSS 6.8No exploitEPSS 1%wpengine · genesis blocksMay 15, 2025
- CVE-2023-2368426Monitor
WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)
MediumCVSS 6.5No exploitEPSS 0%wpengine · wpgraphqlNov 12, 2023
- CVE-2024-4542924Monitor
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5
MediumCVSS 6.1No exploitEPSS 0%wpengine · advanced custom fieldsSep 4, 2024
- CVE-2022-156321Monitor
WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
MediumCVSS 5.3No exploitEPSS 1%wpengine · wpgraphqlJan 16, 2024
- CVE-2024-356321Monitor
Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes
MediumCVSS 5.4No exploitEPSS 0%wpengine · genesis blocksJul 9, 2024