Malware
CVE
Also called Common Vulnerabilities and Exposures.
CVE is a public identifier, like CVE-2024-12345, for one specific vulnerability in one piece of software. It gives everyone the same label for the same hole.
How it is measured
A CVE record names the affected product and version range, a short description, and references to advisories and patches. A severity score under CVSS usually follows. You check exposure by matching your installed versions against those ranges.
For a WordPress site, list plugin names and versions, then look each up in a vulnerability database. A plugin at 2.3.1 with a CVE fixed in 2.3.4 is exposed until you update.
Worked example
A small agency runs 23 client sites. A CVE is published for a form builder plugin: unauthenticated file upload, fixed in 4.2.9. A search of the agency's inventory shows 7 sites on 4.2.5 to 4.2.8.
Those seven are updated within the day, and logs on two of them show POSTs to the vulnerable endpoint the night before. Those two get a full file scan, not just the update.
How it differs
A CVE names one specific flaw in one product. A CWE names the type of weakness, such as injection, that many CVEs share. An n-day is a CVE that is public and has a patch, but not yet installed on your machine. A zero-day has no patch at the time of exploitation, and may have no CVE yet.
Common errors
Reading the score and ignoring whether the vulnerable feature is on. Treating a missing CVE as proof a plugin is safe. Updating the plugin but not checking whether it was already exploited. Counting CVEs per vendor as a quality ranking. Waiting for a monthly maintenance window on an actively exploited one.
In practice
Keep an inventory of every plugin, theme, and library with versions. Subscribe to advisories for the top ones. When a CVE lands, check your inventory the same day, patch the exposed sites first, and look at logs for signs the hole was used before you got there.