Exposure of WordPress
Blogs, CMS2,045
exposure score
2,932,393
sites use
0
exploited
174
critical
CVEs
2,381 resultsCVE-2024-3235MEDIUMEssential Grid <= 3.1.1 - Unauthenticated Private Post DisclosureEPSS 0.7%CVE-2022-41652MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerabilityEPSS 0.7%CVE-2021-24482—Related Posts for WordPress <= 2.0.4 - Authenticated Stored XSS & XFSEPSS 0.7%CVE-2021-24900—Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site ScriptingEPSS 0.7%CVE-2024-11391HIGHAdvanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.7%CVE-2024-12811HIGHTraveler <= 3.1.9 - Authenticated (Contributor+) Local File Inclusion via ShortcodeEPSS 0.7%CVE-2025-10057HIGHWP Import – Ultimate CSV XML Importer for WordPress 7.20 - 7.28 - Authenticated (Subscriber+) Remote Code Execution via Code InjectionEPSS 0.7%CVE-2024-13098MEDIUMWP Email Newsletter <= 1.1 - Reflected XSSEPSS 0.7%CVE-2024-3649MEDIUMContact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price ManipulationEPSS 0.7%CVE-2022-44634MEDIUMWordPress S2W – Import Shopify to WooCommerce plugin <= 1.1.12 - Auth. Arbitrary File Read vulnerabilityEPSS 0.7%CVE-2025-3740HIGHSchool Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password UpdateEPSS 0.7%CVE-2024-5630HIGHInsert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File UploadEPSS 0.7%CVE-2021-24179—Business Directory Plugin < 5.11 - Arbitrary File Upload to RCEEPSS 0.7%CVE-2021-24178—Business Directory Plugin < 5.11.1 - Arbitrary Add/Edit/Delete Form Field to Stored XSSEPSS 0.7%CVE-2025-9990HIGHWordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File InclusionEPSS 0.7%CVE-2021-24502—WP Google Map < 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2026-1400HIGHAI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata EndpointEPSS 0.7%CVE-2024-8392HIGHWordPress Post Grid Layouts with Pagination – Sogrid <= 1.5.6 - Authenticated (Admin+) Local File InclusionEPSS 0.7%CVE-2022-41155MEDIUMWordPress iQ Block Country plugin <= 1.2.18 - Block BYPASS vulnerabilityEPSS 0.7%CVE-2019-25145HIGHContact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injectionEPSS 0.7%
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →