WPScan
First CVE: Mar 18, 2021Active for: 5 years
4,438
CVEs Published
More CVEs Published than 96% of tracked CNAs
739.7
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 11% of tracked CNAs
0.0%
In CISA KEV
Higher KEV Rate than 77% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by WPScan as a CNA, 0.0% affect products that WPScan develops as a vendor.
100.0%
Self-reported: 1Third-party: 4,437
Of all the CVEs published that affect products developed by WPScan, 100.0% are self-published by WPScan as a CNA.
100.0%
Self-published: 1Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by WPScan over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2021
5 years ago
Most Recent CVE
Jul 23, 2026
0 days ago
Top CVEs
All CVEs published by WPScan as a CNA, regardless of affected vendor or product.
4,438 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-63030CRITICAL WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C | Jul 17, 2026 | 9.8 | 96 | YES | YES |
CVE-2022-0441CRITICAL The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | Mar 7, 2022 | 9.8 | 92 | NO | YES |
CVE-2021-24762CRITICAL The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allo | Feb 1, 2022 | 9.8 | 92 | NO | YES |
CVE-2023-5360CRITICAL The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files | Oct 31, 2023 | 9.8 | 91 | NO | YES |
CVE-2021-24931CRITICAL The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (availabl | Dec 6, 2021 | 9.8 | 91 | NO | YES |
CVE-2026-60137CRITICAL WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a | Jul 17, 2026 | 9.1 | 89 | YES | NO |
CVE-2021-25094HIGH The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's uplo | Apr 25, 2022 | 8.1 | 89 | NO | YES |
CVE-2021-24946CRITICAL The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX ac | Dec 13, 2021 | 9.8 | 89 | NO | YES |
CVE-2021-24145HIGH Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by adm | Mar 18, 2021 | 7.2 | 89 | NO | YES |
CVE-2021-24155HIGH The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high priv | Apr 5, 2021 | 7.2 | 88 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA4,438 CVEs
72%
19%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local16 (0.4%)
Network4,418 (99.5%)
Unknown4 (0.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4,360 (98.2%)
High74 (1.7%)
Unknown4 (0.1%)
User Interaction
None1,448 (32.6%)
Unknown4 (0.1%)
Required2,986 (67.3%)
Privileges Required
Low1,291 (29.1%)
High1,241 (28.0%)
None1,902 (42.9%)
Unknown4 (0.1%)
Exploit Exposure
Signals from CVEs in this cna scope (4438 CVEs).
CISA KEV
2 CVEs
0.0% of CVEs· 77th percentile
Metasploit
17 CVEs
0.4% of CVEs· 81st percentile
Nuclei
471 CVEs
10.6% of CVEs· 97th percentile
ExploitDB
71 CVEs
1.6% of CVEs· 86th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by WPScan as a CNA.
Media Mentions
Media articles that mention a CVE ID published by WPScan as a CNA — matched by CVE ID, not by organization name.