wpengine kayıtları
wpengine üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %46,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-306 Missing Authentication for Critical Function3
- CWE-502 Deserialization of Untrusted Data2
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
- WP Engine Bug BountyIntigriti · ödüllü · en çok $2.500
- WP Engine VDPIntigriti · yalnızca bildirim (VDP)
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2023-6933Kavram kanıtı | Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injectionwpengine · better search replace · CWE-502 | Yüksek8,8 | — | %68,0 | 5 Şub 2024 |
53Planlayın | CVE-2019-9879Kavram kanıtı | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratiowpengine · wpgraphql · CWE-306 | Kritik9,8 | — | %46,6 | 10 Haz 2019 |
46Planlayın | CVE-2019-9880Kavram kanıtı | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.wpengine · wpgraphql · CWE-306 | Kritik9,1 | — | %34,8 | 10 Haz 2019 |
40Planlayın | CVE-2024-30225İstismar yok | WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerabilitywpengine, inc. · wp migrate · CWE-502 | Kritik10,0 | — | %0,7 | 28 Mar 2024 |
39İzleyin | CVE-2024-34762İstismar yok | Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerabilitywpengine inc · advanced custom fields pro · CWE-22 | Kritik9,9 | — | %0,6 | 10 Haz 2024 |
35İzleyin | CVE-2023-24421İstismar yok | WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)wpengine · php compatibility checker · CWE-352 | Yüksek8,8 | — | %0,3 | 11 Tem 2023 |
27İzleyin | CVE-2019-9881Kavram kanıtı | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even whwpengine · wpgraphql · CWE-306 | Orta5,3 | — | %18,8 | 10 Haz 2019 |
27İzleyin | CVE-2024-2761İstismar yok | Genesis Blocks < 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Orta6,8 | — | %0,7 | 19 Nis 2024 |
27İzleyin | CVE-2024-3901İstismar yok | Genesis Blocks <= 3.1.3 - Contributor+ Stored XSSwpengine · genesis blocks · CWE-79 | Orta6,8 | — | %0,6 | 15 May 2025 |
26İzleyin | CVE-2023-23684İstismar yok | WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)wpengine · wpgraphql · CWE-918 | Orta6,5 | — | %0,5 | 12 Kas 2023 |
24İzleyin | CVE-2024-45429İstismar yok | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5wpengine · advanced custom fields · CWE-79 | Orta6,1 | — | %0,4 | 4 Eyl 2024 |
21İzleyin | CVE-2022-1563İstismar yok | WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosurewpengine · wpgraphql · CWE-284 | Orta5,3 | — | %0,7 | 16 Oca 2024 |
21İzleyin | CVE-2024-3563İstismar yok | Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributeswpengine · genesis blocks · CWE-79 | Orta5,4 | — | %0,3 | 9 Tem 2024 |
- CVE-2023-693355Planlayın
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
YüksekCVSS 8,8Kavram kanıtıEPSS %68wpengine · better search replace5 Şub 2024
- CVE-2019-987953Planlayın
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratio
KritikCVSS 9,8Kavram kanıtıEPSS %47wpengine · wpgraphql10 Haz 2019
- CVE-2019-988046Planlayın
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.
KritikCVSS 9,1Kavram kanıtıEPSS %35wpengine · wpgraphql10 Haz 2019
- CVE-2024-3022540Planlayın
WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability
KritikCVSS 10,0İstismar yokEPSS %1wpengine, inc. · wp migrate28 Mar 2024
- CVE-2024-3476239İzleyin
Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability
KritikCVSS 9,9İstismar yokEPSS %1wpengine inc · advanced custom fields pro10 Haz 2024
- CVE-2023-2442135İzleyin
WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0wpengine · php compatibility checker11 Tem 2023
- CVE-2019-988127İzleyin
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even wh
OrtaCVSS 5,3Kavram kanıtıEPSS %19wpengine · wpgraphql10 Haz 2019
- CVE-2024-276127İzleyin
Genesis Blocks < 3.1.3 - Contributor+ Stored XSS
OrtaCVSS 6,8İstismar yokEPSS %1wpengine · genesis blocks19 Nis 2024
- CVE-2024-390127İzleyin
Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS
OrtaCVSS 6,8İstismar yokEPSS %1wpengine · genesis blocks15 May 2025
- CVE-2023-2368426İzleyin
WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)
OrtaCVSS 6,5İstismar yokEPSS %0wpengine · wpgraphql12 Kas 2023
- CVE-2024-4542924İzleyin
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5
OrtaCVSS 6,1İstismar yokEPSS %0wpengine · advanced custom fields4 Eyl 2024
- CVE-2022-156321İzleyin
WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
OrtaCVSS 5,3İstismar yokEPSS %1wpengine · wpgraphql16 Oca 2024
- CVE-2024-356321İzleyin
Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes
OrtaCVSS 5,4İstismar yokEPSS %0wpengine · genesis blocks9 Tem 2024