VYPR
Vendor

Wpengine

Products
8
CVEs
20
Across products
20
Status
Private

Products

8

Recent CVEs

20
  • CVE-2019-9879CriJun 10, 2019
    risk 0.70cvss 9.8epss 0.47

    The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

  • CVE-2022-0817CriMay 9, 2022
    risk 0.65cvss 9.8epss 0.12

    The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2019-9880CriJun 10, 2019
    risk 0.58cvss 9.1epss 0.35

    An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

  • CVE-2022-2958HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

  • CVE-2023-6933HigFeb 5, 2024
    risk 0.56cvss 8.8epss 0.68

    The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the…

  • CVE-2022-2593HigAug 22, 2022
    risk 0.47cvss 7.2epss 0.01

    The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks

  • CVE-2025-39446HigMay 19, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.

  • CVE-2024-3901MedMay 15, 2025
    risk 0.44cvss 6.8epss 0.01

    The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

  • CVE-2024-2761MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.01

    The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

  • CVE-2024-3563MedJul 9, 2024
    risk 0.42cvss 6.4epss 0.00

    The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

  • CVE-2023-2173MedAug 31, 2023
    risk 0.42cvss 6.5epss 0.01

    The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler,…

  • CVE-2022-41987MedMay 25, 2023
    risk 0.41cvss 6.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.

  • CVE-2024-45429MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the…

  • CVE-2019-9881MedJun 10, 2019
    risk 0.39cvss 5.3epss 0.19

    The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

  • CVE-2022-1563MedJan 16, 2024
    risk 0.35cvss 5.3epss 0.01

    The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

  • CVE-2023-2171MedAug 31, 2023
    risk 0.35cvss 5.4epss 0.00

    The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

  • CVE-2023-24421MedJul 11, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions.

  • CVE-2023-2174MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.00

    The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-2172MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.01

    The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_update_steps_ajax_handler, badgeos_update_award_steps_ajax_handler,…

  • CVE-2023-23684MedNov 13, 2023
    risk 0.22cvss 4.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.