Malware

CVE

Also called Common Vulnerabilities and Exposures.

CVE is a public identifier, like CVE-2024-12345, for one specific vulnerability in one piece of software. It gives everyone the same label for the same hole.

How it is measured

A CVE record names the affected product and version range, a short description, and references to advisories and patches. A severity score under CVSS usually follows. You check exposure by matching your installed versions against those ranges.

For a WordPress site, list plugin names and versions, then look each up in a vulnerability database. A plugin at 2.3.1 with a CVE fixed in 2.3.4 is exposed until you update.

Worked example

A small agency runs 23 client sites. A CVE is published for a form builder plugin: unauthenticated file upload, fixed in 4.2.9. A search of the agency's inventory shows 7 sites on 4.2.5 to 4.2.8.

Those seven are updated within the day, and logs on two of them show POSTs to the vulnerable endpoint the night before. Those two get a full file scan, not just the update.

How it differs

A CVE names one specific flaw in one product. A CWE names the type of weakness, such as injection, that many CVEs share. An n-day is a CVE that is public and has a patch, but not yet installed on your machine. A zero-day has no patch at the time of exploitation, and may have no CVE yet.

Common errors

Reading the score and ignoring whether the vulnerable feature is on. Treating a missing CVE as proof a plugin is safe. Updating the plugin but not checking whether it was already exploited. Counting CVEs per vendor as a quality ranking. Waiting for a monthly maintenance window on an actively exploited one.

In practice

Keep an inventory of every plugin, theme, and library with versions. Subscribe to advisories for the top ones. When a CVE lands, check your inventory the same day, patch the exposed sites first, and look at logs for signs the hole was used before you got there.

See also

CWE, N-day

Sources

Count this on a real site.

Watch my website