Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpengine

First CVE: Jun 10, 2019Active for: 7 yearsTotal CVEs: 11
37.5
VTI Score
Medium

WPEngine develops a focused portfolio of WordPress hosting infrastructure and open-source WordPress plugins, including widely adopted developer tools such as WPGraphQL, Advanced Custom Fields, and Genesis Blocks that extend WordPress functionality across many sites. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the exposure recurs through web-application weakness classes including cross-site scripting, missing authentication, cross-site request forgery, and untrusted deserialization that are endemic to PHP-based plugins and server-side WordPress customization. Defenders should prioritize patching this vendor's products, particularly those with internet-facing administrative surfaces, and monitor plugin repositories for affected versions; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpengine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 10, 2019
7 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6933CRITICAL
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes
Feb 5, 20249.878NOYES
CVE-2019-9879CRITICAL
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the r
Jun 10, 20199.875NOYES
CVE-2019-9880CRITICAL
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress u
Jun 10, 20199.164NOYES
CVE-2019-9881MEDIUM
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
Jun 10, 20195.343NOYES
CVE-2023-24421HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions.
Jul 11, 20238.825NONO
CVE-2024-2761MEDIUM
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct
Apr 19, 20246.820NONO
CVE-2024-3901MEDIUM
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (li
May 15, 20256.819NONO
CVE-2023-23684MEDIUM
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
Nov 13, 20236.519NONO
CVE-2024-45429MEDIUM
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'c
Sep 4, 20246.118NONO
CVE-2024-3563MEDIUM
The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient
Jul 9, 20245.418NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
9%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low3 (27.3%)
High1 (9.1%)
None7 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
36.4% of CVEs· 98th percentile
ExploitDB
3 CVEs
27.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpengine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpengine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpengine's Products

View all 5 CNAs →

Top CWEs