WPScan is a vulnerability disclosure entity that has produced advisories centered on WordPress and related ecosystem products, with reported exposure focused on WP Cloudy. The durable signal from the vendor's disclosures centers on SQL injection vulnerabilities, a class characteristic of database query construction in WordPress plugins and integrations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by WPScan over time
Of all the CVEs published by WPScan as a CNA, 0.0% affect products that WPScan develops as a vendor.
Of all the CVEs published that affect products developed by WPScan, 100.0% are self-published by WPScan as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24864HIGH The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Inject | Feb 28, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by WPScan.
Media articles that mention a CVE ID that affects a product developed by WPScan — matched by CVE ID, not by vendor name.