ValvePress Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for ValvePress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

0

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

ValvePress KEVs Added by Year

Loading...

2 ValvePress KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-4374

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to...

High Not in CISA 25 Apr 2026
CVE-2024-27956

WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability

High Not in CISA 26 Jun 2025

Common Vulnerability Classes (CWE)

  • CWE-862 — Missing Authorization 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology