WPScan

First CVE: Mar 18, 2021Active for: 5 years
4,438
CVEs Published
More CVEs Published than 96% of tracked CNAs
739.7
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 11% of tracked CNAs
0.0%
In CISA KEV
Higher KEV Rate than 77% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by WPScan as a CNA, 0.0% affect products that WPScan develops as a vendor.

100.0%
Self-reported: 1Third-party: 4,437

Of all the CVEs published that affect products developed by WPScan, 100.0% are self-published by WPScan as a CNA.

100.0%
Self-published: 1Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by WPScan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2021
5 years ago
Most Recent CVE
Jul 23, 2026
0 days ago

Top CVEs

All CVEs published by WPScan as a CNA, regardless of affected vendor or product.

4,438 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C
Jul 17, 20269.896YESYES
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
Mar 7, 20229.892NOYES
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allo
Feb 1, 20229.892NOYES
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files
Oct 31, 20239.891NOYES
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (availabl
Dec 6, 20219.891NOYES
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a
Jul 17, 20269.189YESNO
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's uplo
Apr 25, 20228.189NOYES
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX ac
Dec 13, 20219.889NOYES
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by adm
Mar 18, 20217.289NOYES
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high priv
Apr 5, 20217.288NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA4,438 CVEs
Severity distribution among all CVEs352,101 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local16 (0.4%)
Network4,418 (99.5%)
Unknown4 (0.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4,360 (98.2%)
High74 (1.7%)
Unknown4 (0.1%)
User Interaction
None1,448 (32.6%)
Unknown4 (0.1%)
Required2,986 (67.3%)
Privileges Required
Low1,291 (29.1%)
High1,241 (28.0%)
None1,902 (42.9%)
Unknown4 (0.1%)

Exploit Exposure

Signals from CVEs in this cna scope (4438 CVEs).

CISA KEV
2 CVEs
0.0% of CVEs· 77th percentile
Metasploit
17 CVEs
0.4% of CVEs· 81st percentile
Nuclei
471 CVEs
10.6% of CVEs· 97th percentile
ExploitDB
71 CVEs
1.6% of CVEs· 86th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by WPScan as a CNA.

Media Mentions

Media articles that mention a CVE ID published by WPScan as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs