wordpress-develop
WordPress- Software type
- —
- Catalog vulnerabilities
- 17
Severity across 17 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 17 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, wordpress-develop has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of wordpress-develop and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2024-31211Remote Code Execution in `WP_HTML_Token` | Exploitation statusNot known exploited | FixYes | Published04/04/2024 | SeverityMedium |
CVE-2024-31210PHP file upload bypass via Plugin installer | Exploitation statusNot known exploited | FixYes | Published04/04/2024 | SeverityHigh |
CVE-2022-21662Stored XSS in WordPress | Exploitation statusNot known exploited | FixYes | Published01/06/2022 | SeverityHigh |
CVE-2022-21663Authenticated Object Injection in Multisites in WordPress | Exploitation statusPublic exploit | FixYes | Published01/06/2022 | SeverityMedium |
CVE-2022-21664SQL injection in WordPress | Exploitation statusNot known exploited | FixYes | Published01/06/2022 | SeverityHigh |
CVE-2022-21661SQL injection in WordPress | Exploitation statusPublic exploit | FixYes | Published01/06/2022 | SeverityHigh |
CVE-2021-39203Private data disclosure/privilege escalation through the block editor in Wordpress | Exploitation statusNot confirmed | FixYes | Published09/09/2021 | SeverityMedium |
CVE-2021-39202WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget | Exploitation statusNot confirmed | FixYes | Published09/09/2021 | SeverityHigh |
CVE-2021-39201Authenticated cross-site scripting (XSS) in WordPress editor | Exploitation statusNot confirmed | FixYes | Published09/09/2021 | SeverityHigh |
CVE-2021-39200Information Disclosure in wp_die() via JSONP in wordpress | Exploitation statusNot confirmed | FixYes | Published09/09/2021 | SeverityMedium |
CVE-2021-29450WordPress Authenticated disclosure of password-protected posts and pages | Exploitation statusNot confirmed | FixYes | Published04/15/2021 | SeverityMedium |
CVE-2021-29447WordPress Authenticated XXE attack when installation is running PHP 8 | Exploitation statusNot confirmed | FixYes | Published04/15/2021 | SeverityHigh |
CVE-2020-4047Authenticated XSS via media attachment page in WordPress | Exploitation statusNot confirmed | FixYes | Published06/12/2020 | SeverityMedium |
CVE-2020-4048Open redirect in wp_validate_redirect() in WordPress | Exploitation statusNot confirmed | FixYes | Published06/12/2020 | SeverityMedium |
CVE-2020-4049Authenticated self-XSS via theme uploads in WordPress | Exploitation statusNot confirmed | FixYes | Published06/12/2020 | SeverityLow |
CVE-2020-4050set-screen-option filter misuse by plugins leading to privilege escalation in WordPress | Exploitation statusNot confirmed | FixYes | Published06/12/2020 | SeverityLow |
CVE-2020-4046Authenticated XSS through embed block in WordPress | Exploitation statusNot confirmed | FixYes | Published06/12/2020 | SeverityMedium |