Exposición de WordPress

Blogs, CMS
2065
score de exposición
2.932.393
sitios usan
0
en explotación
174
críticos
Análisis Vexday

WordPress acumula 2.381 CVEs catalogadas, com 174 classificadas como críticas e 95 surgidas apenas nos últimos 90 dias, o que indica um fluxo contínuo e elevado de novas vulnerabilidades para a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), refletindo a superfície de ataque característica de ambientes com grande volume de plugins e temas de terceiros. Embora a taxa de exploração ativa esteja abaixo da média geral do catálogo CISA KEV, o EPSS máximo observado chega a 0,977, e o CVE-2022-21661 — uma vulnerabilidade de consulta SQL — apresenta EPSS de 0,978, sinalizando altíssima probabilidade de exploração e merecendo atenção prioritária em qualquer plano de remediação. Equipes de segurança devem monitorar ativamente o ritmo de publicações recentes e manter políticas rigorosas de atualização, especialmente em instalações com extensões de terceiros.

CVEs

2387 resultados
CVE-2023-6923MEDIUMMatomo <= 4.15.3 - Reflected Cross-Site Scripting via idsiteEPSS 0.5%CVE-2022-27853MEDIUMWordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2023-41798MEDIUMWordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV InjectionEPSS 0.5%CVE-2022-45369MEDIUMWordPress Plugin for Google Reviews plugin <= 2.2.2 - Auth. Broken Access Control vulnerabilityEPSS 0.5%CVE-2024-52376CRITICALWordPress Boat Rental Plugin for WordPress plugin <= 1.0.1 - Arbitrary File Upload vulnerabilityEPSS 0.5%CVE-2025-24588MEDIUMWordPress Patreon WordPress plugin <= 1.9.1 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2024-2200MEDIUMContact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_subjectEPSS 0.5%CVE-2024-2428MEDIUMThe Ultimate Video Player For WordPress < 2.2.3 - Contributor+ Stored XSSEPSS 0.5%CVE-2022-29426MEDIUMWordPress Slideshow, Image Slider by 2J plugin <= 1.3.54 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2022-47429MEDIUMWordPress Coming Soon Landing Page and Maintenance Mode WordPress Plugin plugin <= 2.2.0 - Broken Access ControlEPSS 0.5%CVE-2022-43482MEDIUMWordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerabilityEPSS 0.5%CVE-2022-41692MEDIUMWordPress Appointment Hour Booking plugin <= 1.3.71 - Missing Authorization vulnerabilityEPSS 0.5%CVE-2024-5973CRITICALMasterStudy LMS < 3.3.24 - Privilege Escalation to InstructorEPSS 0.5%CVE-2022-2398WP Comments Fields < 4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2022-2395weForms < 1.6.14 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2022-2305WordPress Popup <= 1.9.3.8 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-25056Ninja Forms < 3.6.10 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-25066Ninja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting via ImportEPSS 0.5%CVE-2022-2151Best Contact Management Software <= 3.7.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-5527HIGHBusiness Directory Plugin <= 6.4.3 - Authenticated (Author+) CSV InjectionEPSS 0.5%

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →