Wordfence

First CVE: Jul 7, 2021Active for: 5 years
10,500
CVEs Published
More CVEs Published than 98% of tracked CNAs
1750.0
Avg CVEs / Year
More Avg CVEs / Year than 99% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Wordfence as a CNA, 0.0% affect products that Wordfence develops as a vendor.

100.0%
Self-reported: 1Third-party: 10,499

Of all the CVEs published that affect products developed by Wordfence, 33.3% are self-published by Wordfence as a CNA.

33.3%
66.7%
Self-published: 1Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Wordfence over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2021
5 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Wordfence as a CNA, regardless of affected vendor or product.

10,500 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no
Nov 16, 20249.893NOYES
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to
Dec 15, 20239.893NOYES
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user c
Nov 15, 20249.891NOYES
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sort
Mar 13, 20249.890NOYES
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification
Jan 11, 20249.890NOYES
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa
Apr 19, 20228.889NOYES
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to
Dec 3, 20259.888NOYES
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the '
Nov 5, 20259.888NOYES
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient
Sep 6, 20239.888NOYES
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. T
Mar 28, 20259.887NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA10,500 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local2 (0.0%)
Network10,495 (100.0%)
Unknown1 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.0%)
Attack Complexity
Low10,063 (95.8%)
High436 (4.2%)
Unknown1 (0.0%)
User Interaction
None7,105 (67.7%)
Unknown1 (0.0%)
Required3,394 (32.3%)
Privileges Required
Low5,334 (50.8%)
High818 (7.8%)
None4,347 (41.4%)
Unknown1 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (10500 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
38 CVEs
0.4% of CVEs· 81st percentile
Nuclei
253 CVEs
2.4% of CVEs· 87th percentile
ExploitDB
35 CVEs
0.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Wordfence as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Wordfence as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs