WPEngine develops a focused portfolio of WordPress hosting infrastructure and open-source WordPress plugins, including widely adopted developer tools such as WPGraphQL, Advanced Custom Fields, and Genesis Blocks that extend WordPress functionality across many sites. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the exposure recurs through web-application weakness classes including cross-site scripting, missing authentication, cross-site request forgery, and untrusted deserialization that are endemic to PHP-based plugins and server-side WordPress customization. Defenders should prioritize patching this vendor's products, particularly those with internet-facing administrative surfaces, and monitor plugin repositories for affected versions; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpengine over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6933CRITICAL The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes | Feb 5, 2024 | 9.8 | 78 | NO | YES |
CVE-2019-9879CRITICAL The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the r | Jun 10, 2019 | 9.8 | 75 | NO | YES |
CVE-2019-9880CRITICAL An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress u | Jun 10, 2019 | 9.1 | 64 | NO | YES |
CVE-2019-9881MEDIUM The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | Jun 10, 2019 | 5.3 | 43 | NO | YES |
CVE-2023-24421HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions. | Jul 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-2761MEDIUM The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct | Apr 19, 2024 | 6.8 | 20 | NO | NO |
CVE-2024-3901MEDIUM The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (li | May 15, 2025 | 6.8 | 19 | NO | NO |
CVE-2023-23684MEDIUM Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5. | Nov 13, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-45429MEDIUM Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'c | Sep 4, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-3563MEDIUM The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient | Jul 9, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpengine.
Media articles that mention a CVE ID that affects a product developed by Wpengine — matched by CVE ID, not by vendor name.