CVE security advisories and vulnerability history for wordpress-develop by WordPress.
26
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
5
Public exploits
PoC or exploit code
7.2
Avg CVSS
2016–2024
Last updated
Overview
WordPress wordpress-develop has 26 published CVE records since 2016, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 5 have a known public exploit. The average CVSS base score across scored CVEs is 7.2.
This page aggregates every publicly disclosed vulnerability (CVE) affecting WordPress wordpress-develop, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of WordPress wordpress-develop's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical6
High8
Medium10
Low2
In CISA’s Known Exploited Vulnerabilities catalog
0
None of WordPress wordpress-develop's CVEs are currently listed in CISA's KEV catalog.
Public exploits
5
5 of WordPress wordpress-develop's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every WordPress wordpress-develop version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about WordPress wordpress-develop vulnerabilities.
How many CVEs does WordPress wordpress-develop have?
WordPress wordpress-develop has 26 published CVE records since 2016.
How many WordPress wordpress-develop CVEs are in CISA KEV?
None of WordPress wordpress-develop's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for WordPress wordpress-develop vulnerabilities?
Yes — 5 of WordPress wordpress-develop's CVEs have a known public exploit.
Which versions of WordPress wordpress-develop are affected?
80 distinct WordPress wordpress-develop versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in WordPress wordpress-develop CVEs?
WordPress wordpress-develop's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
How many critical WordPress wordpress-develop vulnerabilities are there?
WordPress wordpress-develop has 6 critical and 8 high-severity CVEs.
What is the average severity of WordPress wordpress-develop CVEs?
The average CVSS base score across WordPress wordpress-develop's scored CVEs is 7.2.