WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload
high
WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0.3. This is due to insufficient validation in the `WP_Image_Editor_Imagick::load()` image-processing path before passing uploaded files or streams to Imagick, which can interpret attacker-supplied ima...
- CVSS:
- 8.8
- Affected:
- 4.7.0 – 4.7.34, 4.8.0 – 4.8.29, 4.9.0 – 4.9.30, 5.0.0 – 5.0.26, 5.1.0 – 5.1.23, 5.2.0 – 5.2.25, 5.3.0 – 5.3.22, 5.4.0 – 5.4.20, 5.5.0 – 5.5.19, 5.6.0 – 5.6.18, 5.7.0 – 5.7.16, 5.8.0 – 5.8.14, 5.9.0 – 5.9.15, 6.0.0 – 6.0.13, 6.1.0 – 6.1.11, 6.2.0 – 6.2.10, 6.3.0 – 6.3.9, 6.4.0 – 6.4.9, 6.5.0 – 6.5.9, 6.6.0 – 6.6.6, 6.7.0 – 6.7.6, 6.8.0 – 6.8.7, 6.9.0 – 6.9.6, 7.0.0 – 7.0.3
- Fixed in:
- 4.7.35
- Disclosed:
- Aug 12, 2026
CVE-2026-65640 on NVD →
WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Emoji Settings Element
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the emoji settings element in all versions up to, and including, 7.0.2 due to insufficient restrictions on submitted post content. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter
medium
WordPress Core is vulnerable to Reflected Cross-Site Scripting via the 'log' parameter in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping of the authentication error messages rendered on the login screen. This makes it possible for unauthenticated attackers to inject...
- CVSS:
- 6.1
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
CVE-2026-64638 on NVD →
WordPress Core <= 7.0.2 - Unauthenticated Blind Server-Side Request Forgery
medium
WordPress Core is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 7.0.2 due to insufficient validation of the destination address, as not all reserved and internal IP address ranges are blocked. This makes it possible for unauthenticated attackers to make web requests to arbitrary...
- CVSS:
- 5.8
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Authenticated (Author+) CSS Injection
medium
WordPress Core is vulnerable to CSS Injection in all versions up to, and including, 7.0.2 due to insufficient sanitization of user supplied CSS. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary CSS into posts, altering the appearance and content of pages render...
- CVSS:
- 5.5
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Unauthenticated Sensitive Information Exposure via Comment Feeds
medium
WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.2 via the comment feeds due to insufficient restrictions on internal notes, which are not excluded from feed output. This makes it possible for unauthenticated attackers to extract the contents of internal notes tha...
- CVSS:
- 5.3
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Quick Edit
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via Quick Edit in all versions up to, and including, 7.0.2 due to insufficient escaping of user display names. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 4.9
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Email Change Confirmation Bypass
medium
WordPress Core is vulnerable to an Email Change Confirmation Bypass in all versions up to, and including, 7.0.2 due to inconsistent validation of the new email address when a user profile is updated. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email address...
- CVSS:
- 4.3
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Site Creation on Multisite
medium
WordPress Core is vulnerable to unauthorized site creation due to a missing check on the active signup policy in the 'gimmeanotherblog' signup action in all versions up to, and including, 7.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new sites on a multisit...
- CVSS:
- 4.3
- Affected:
- 4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
- Fixed in:
- 4.7.34
- Disclosed:
- Aug 8, 2026
WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion
critical
WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoint (/wp-json/batch/v1). This is due to a route/validation desynchronization that allows a validated sub-request to be dispatched to an unintended callback, bypassing the allow_batch restriction, with...
- CVSS:
- 9.8
- Affected:
- 6.9 – 6.9.5, 7.0 – 7.0.2
- Fixed in:
- 6.9.5
- Disclosed:
- Jul 17, 2026
CVE-2026-63030 on NVD →
WordPress Core 6.8 - 7.0.1 - Unauthenticated SQL Injection via author__not_in Parameter
high
WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 - 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...
- CVSS:
- 7.5
- Affected:
- 6.8 – 6.8.5, 6.9 – 6.9.5, 7.0 – 7.0.2
- Fixed in:
- 6.8.6
- Disclosed:
- Jul 17, 2026
CVE-2026-60137 on NVD →
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
medium
WordPress core is vulnerable to XML External Entity (XXE) Injection via the bundled getID3 library in all versions up to and including 6.9.1. This is due to the `GETID3_LIBXML_OPTIONS` constant including the `LIBXML_NOENT` flag, which enables XML entity substitution during parsing. When WordPress processes media files...
- CVSS:
- 6.5
- Affected:
- 6.8 – 6.8.3, 6.9 – 6.9.1
- Fixed in:
- 6.8.4
- Disclosed:
- Mar 10, 2026
WordPress <= 6.9.1 - Unauthenticated Blind Server-Side Request Forgery via XML-RPC Pingback Discovery
medium
WordPress core is vulnerable to Blind Server-Side Request Forgery in all versions up to and including 6.9.1. This is due to the `WP_HTTP_IXR_Client` class using `wp_remote_post()` instead of the safer `wp_safe_remote_post()` when making outgoing XML-RPC pingback requests. This makes it possible for unauthenticated atta...
- CVSS:
- 5.8
- Affected:
- 6.8 – 6.8.3, 6.9 – 6.9.1
- Fixed in:
- 6.8.4
- Disclosed:
- Mar 10, 2026
WordPress <= 6.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Navigation Menu Items
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via admin settings in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 4.4
- Affected:
- 6.8 – 6.8.3, 6.9 – 6.9.1
- Fixed in:
- 6.8.4
- Disclosed:
- Mar 10, 2026
WordPress <= 6.9.1 - Cross-Site Scripting via Client-Side Template Override in Admin Area
medium
WordPress core is vulnerable to Cross-Site Scripting via client-side template overriding in the admin area in all versions up to and including 6.9.1. The `wp.template()` JavaScript function uses `document.getElementById()` to locate templates, which matches any HTML element by ID regardless of element type. WordPress a...
- CVSS:
- 4.4
- Affected:
- 6.8 – 6.8.3, 6.9 – 6.9.1
- Fixed in:
- 6.8.4
- Disclosed:
- Mar 10, 2026
WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API
medium
WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments c...
- CVSS:
- 4.3
- Affected:
- 6.9 – 6.9.1
- Fixed in:
- 6.9.2
- Disclosed:
- Mar 10, 2026
CVE-2026-3906 on NVD →
WordPress <= 6.9.1 - Missing Authorization to Authenticated (Author+) Sensitive Information Disclosure via query-attachments AJAX Endpoint
medium
WordPress core is vulnerable to Missing Authorization in all versions up to and including 6.9.1. This is due to a missing capability check on the `uploadedToTitle` and `uploadedToLink` fields in the `wp_prepare_attachment_for_js()` function. When querying media attachments via the AJAX `query-attachments` endpoint, the...
- CVSS:
- 4.3
- Affected:
- 6.8 – 6.8.3, 6.9 – 6.9.1
- Fixed in:
- 6.8.4
- Disclosed:
- Mar 10, 2026
WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever...
- CVSS:
- 6.4
- Affected:
- up to 4.7, 4.7 – 4.7.30, 4.8 – 4.8.26, 4.9 – 4.9.27, 5.0 – 5.0.23, 5.1 – 5.1.20, 5.2 – 5.2.22, 5.3 – 5.3.19, 5.4 – 5.4.17, 5.5 – 5.5.16, 5.6 – 5.6.15, 5.7 – 5.7.13, 5.8 – 5.8.11, 5.9 – 5.9.11, 6.0 – 6.0.10, 6.1 – 6.1.8, 6.2 – 6.2.7, 6.3 – 6.3.6, 6.4 – 6.4.6, 6.5 – 6.5.6, 6.6 – 6.6.3, 6.7 – 6.7.3, 6.8 – 6.8.2
- Fixed in:
- 4.7.31
- Disclosed:
- Sep 22, 2025
CVE-2025-58674 on NVD →
WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure
medium
WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts they should not have access to.
- CVSS:
- 4.3
- Affected:
- 4.7 – 4.7.30, 4.8 – 4.8.26, 4.9 – 4.9.27, 5.0 – 5.0.23, 5.1 – 5.1.20, 5.2 – 5.2.22, 5.3 – 5.3.19, 5.4 – 5.4.17, 5.5 – 5.5.16, 5.6 – 5.6.15, 5.7 – 5.7.13, 5.8 – 5.8.11, 5.9 – 5.9.11, 6.0 – 6.0.10, 6.1 – 6.1.8, 6.2 – 6.2.7, 6.3 – 6.3.6, 6.4 – 6.4.6, 6.5 – 6.5.6, 6.6 – 6.6.3, 6.7 – 6.7.3, 6.8 – 6.8.2
- Fixed in:
- 4.7.31
- Disclosed:
- Sep 22, 2025
CVE-2025-58246 on NVD →
WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
- Fixed in:
- 5.9.10
- Disclosed:
- Jun 24, 2024
CVE-2024-31111 on NVD →
WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
- Fixed in:
- 5.9.10
- Disclosed:
- Jun 24, 2024
CVE-2024-6307 on NVD →
WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal
medium
WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This makes it possible for authenticated attackers, with Contributor-level access and above, to include arbitrary HTML Files on sites running Windows.
- CVSS:
- 4.3
- Affected:
- up to 4.1, 4.1 – 4.1.40, 4.2 – 4.2.37, 4.3 – 4.3.33, 4.4 – 4.4.32, 4.5 – 4.5.31, 4.6 – 4.6.28, 4.7 – 4.7.28, 4.8 – 4.8.24, 4.9 – 4.9.25, 5.0 – 5.0.21, 5.1 – 5.1.18, 5.2 – 5.2.20, 5.3 – 5.3.17, 5.4 – 5.4.15, 5.5 – 5.5.14, 5.6 – 5.6.13, 5.7 – 5.7.11, 5.8 – 5.8.9, 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
- Fixed in:
- 4.1.41
- Disclosed:
- Jun 24, 2024
CVE-2024-32111 on NVD →
WordPress Core < 6.5.2 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
high
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 7.2
- Affected:
- 6.0 – 6.0.7, 6.1 – 6.1.5, 6.2 – 6.2.4, 6.3 – 6.3.3, 6.4 – 6.4.3, 6.5 – 6.5.1
- Fixed in:
- 6.0.8
- Disclosed:
- Apr 9, 2024
CVE-2024-4439 on NVD →
WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink
medium
WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.
- CVSS:
- 5.3
- Affected:
- up to 6.4.3
- Fixed in:
- 6.5
- Disclosed:
- Apr 4, 2024
CVE-2023-5692 on NVD →
WordPress Core 6.4.0 - 6.4.1 - Remote Code Execution POP Chain
critical
WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there being a magic method __destruct in the WP_HTML_Token class. This makes it possible for attackers to achieve remote code execution when another deserialization/PHP Object Injection vulnerability is pre...
- CVSS:
- 9.8
- Affected:
- 6.4.0 – 6.4.0, 6.4.1 – 6.4.1
- Fixed in:
- 6.4.2
- Disclosed:
- Dec 6, 2023
CVE-2024-31211 on NVD →
WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges and above to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 5.9.8
- Disclosed:
- Oct 12, 2023
CVE-2023-38000 on NVD →
WordPress Core 6.3 - 6.3.1 - Authenticated(Contributor+) Cross-Site Scripting via Footnotes Block
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the footnotes block in versions between 6.3 and 6.3.1 due to insufficient input sanitization and output escaping on the footnotes block. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- 6.3 – 6.3.1
- Fixed in:
- 6.3.2
- Disclosed:
- Oct 12, 2023
WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests
medium
WordPress Core is vulnerable to Reflected Cross-Site Scripting via the ‘success_url’ and 'reject_url' parameters when requesting application passwords in versions between 5.6 and 6.3.1 due to insufficient input sanitization and output escaping of pseudo protocol URIs. This makes it possible for unauthenticated attacker...
- CVSS:
- 6.1
- Affected:
- 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 5.6.12
- Disclosed:
- Oct 12, 2023
WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode
medium
WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of input validation on the 'shortcode' parameter in the parse_media_shortcode AJAX function. This allows authenticated attackers, with subscriber-level privileges and above, to execute arbitrary shortcode...
- CVSS:
- 5.4
- Affected:
- up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 4.1.39
- Disclosed:
- Oct 12, 2023
WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint
medium
WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column. This can allow unauthent...
- CVSS:
- 5.3
- Affected:
- 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 4.7.27
- Disclosed:
- Oct 12, 2023
CVE-2023-5561 on NVD →
WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning
medium
WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases where the X-HTTP-Method-Override header was sent in a request to a REST endpoint and the endpoint returned a 4xx error, the error could be cached, resulting in denial of service.
- CVSS:
- 5.3
- Affected:
- 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 4.7.27
- Disclosed:
- Oct 12, 2023
WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts
medium
WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments listing. This allows authenticated users, with contributor-level privileges or above, to view comments on protected posts.
- CVSS:
- 4.3
- Affected:
- up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
- Fixed in:
- 4.1.39
- Disclosed:
- Oct 12, 2023
CVE-2023-39999 on NVD →
WordPress Core < 6.2.2 - Shortcode Execution in User Generated Content
medium
WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require Subscriber or Contributor-leve...
- CVSS:
- 6.5
- Affected:
- 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2
- Fixed in:
- 5.9.7
- Disclosed:
- May 19, 2023
WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content
medium
WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require Subscriber or Contributor-level...
- CVSS:
- 6.5
- Affected:
- 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
- Fixed in:
- 5.9.6
- Disclosed:
- May 19, 2023
WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes
medium
WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it possible for authenticated attackers with contributor-level and above permissions to embed arbitrary content in HTML comments on the page, though Cross-Site Scripting may be possible when combined with a...
- CVSS:
- 6.4
- Affected:
- up to 4.1, 4.1 – 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
- Fixed in:
- 4.1.38
- Disclosed:
- May 16, 2023
WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery
medium
WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient validation of the protocol in the response when processing oEmbed discovery. This makes it possible for authenticated attackers with contributor-level and above permissions to use a crafted oEmbed payl...
- CVSS:
- 6.4
- Affected:
- up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
- Fixed in:
- 4.1.38
- Disclosed:
- May 16, 2023
WordPress Core < 6.2.1 - Directory Traversal
medium
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form,...
- CVSS:
- 5.4
- Affected:
- up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
- Fixed in:
- 4.1.38
- Disclosed:
- May 16, 2023
CVE-2023-2745 on NVD →
WordPress Core < 6.2.1 - Cross-Site Request Forgery
medium
WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the ‘wp_ajax_set_attachment_thumbnail’ AJAX function in versions up to, and including, 6.2. This allows unauthenticated users to update the thumbnail image associated with existing attachments, granted they can trick an authen...
- CVSS:
- 4.3
- Affected:
- up to 4.1, 4.1 – 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
- Fixed in:
- 4.1.38
- Disclosed:
- May 16, 2023
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
critical
WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where “AND” and “OR” present in the query. This may make it possible for attackers to achieve SQL Injection when another plugin or theme is installed on the site that allows WP_Date_Query to be used insecurely...
- CVSS:
- 9.8
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection
high
WordPress Core is vulnerable to SQL Injection in the Media Library that can be leveraged to exploit a Reflected Cross-Site Scripting issue in versions up to 6.0.3. This is due to insufficient escaping on user supplied values passed to a SQL query. This makes it possible for an attacker to achieved JavaScript code exec...
- CVSS:
- 8.8
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
CVE-2022-43497 on NVD →
WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php
high
WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to the fact that the any request to wp-trackback.php would assume the identity of the user whose cookies are sent with the request. This would make it possible for an unauthenticated user to trigger a tr...
- CVSS:
- 8.8
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Stored Cross-Site Scripting via wp-mail.php
high
WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validation on what level the user was sending the email post and therefore did not perform any sanitization on the submitted post data. This meant that users without the unfiltered_html capability, with acce...
- CVSS:
- 7.2
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
CVE-2022-43504 on NVD →
WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks
medium
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...
- CVSS:
- 6.4
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
CVE-2022-43500 on NVD →
WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to insufficient escaping on the 'Blog Name' value that could be edited and become executable with the right payload while in the theme customizer. This would make it possible for authenticated attacker wi...
- CVSS:
- 5.5
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3. This is due to insufficient escaping and sanitization on the values being stored during a comment update. This makes it possible for authenticated users with high level permissions, such as an edito...
- CVSS:
- 5.5
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Open Redirect
medium
WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Referer' header and _wp_http_referer request parameter when a user accesses a link with an expired or invalid nonce. This would make it possible for an attacker to redirect a victim to a potentially mal...
- CVSS:
- 5.4
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Information Disclosure (Email Address)
medium
WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality is enabled, it may log post author's email addresses in a way that may be publicly accessible. This could make it possible for attackers to steal post author's email addresses and use that for further...
- CVSS:
- 5.3
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
CVE-2022-43504 on NVD →
WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API
medium
WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a c...
- CVSS:
- 4.3
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Shared User Instance Weakness
low
WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS and CSRF in wp-mail.php and wp-trackback.php vulnerabilities. The previous functionality may ha...
- CVSS:
- 3.7
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)
low
WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a con...
- CVSS:
- 3.7
- Affected:
- up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
- Fixed in:
- 3.7.40
- Disclosed:
- Oct 18, 2022
WordPress Core - All known versions - Unauthenticated Blind Server Side Request Forgery
medium
WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This is due to a Time-of-Check-Time-of-Use (TOC-TOU) race condition between validation checks and HTTP requests that makes it possible for URLs to be validated and then changed before being used by the soft...
- CVSS:
- 4
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Sep 6, 2022
CVE-2022-3590 on NVD →
WordPress Core < 6.0.2 - Authenticated SQL Injection
high
WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via the LIMIT parameter passed through the get_bookmarks function. This can be exploited on default WordPress installations by users with high-level privileges, such as an editor or administrator, and it...
- CVSS:
- 8
- Affected:
- up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
- Fixed in:
- 3.7.39
- Disclosed:
- Aug 30, 2022
WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function
medium
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that ex...
- CVSS:
- 4.9
- Affected:
- up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
- Fixed in:
- 3.7.39
- Disclosed:
- Aug 30, 2022
CVE-2022-4973 on NVD →
WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors
medium
WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicious content is injected into plugin code that triggers when an error occurs during plugin de-activation or during deletion. This requires an attacker have access to the modify the error message that is...
- CVSS:
- 4.4
- Affected:
- up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
- Fixed in:
- 3.7.39
- Disclosed:
- Aug 30, 2022
WordPress Core < 5.9.1 - jQuery Prototype Pollution
high
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3, 5.9 – 5.9.1
- Fixed in:
- 3.7.38
- Disclosed:
- Mar 11, 2022
CVE-2021-20083 on NVD →
WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
WordPress Core in versions 5.9 - 5.9.1 is vulnerable to Contributor+ stored Cross-Site Scripting via the double JSON encoded payloads set in the 'isGlobalStylesUserThemeJSON' parameter which is updatable via the post editor.
- CVSS:
- 6.4
- Affected:
- 5.9 – 5.9.2
- Fixed in:
- 5.9.2
- Disclosed:
- Mar 11, 2022
WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor
medium
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3, 5.9 – 5.9.1
- Fixed in:
- 3.7.38
- Disclosed:
- Mar 11, 2022
WordPress Core < 5.8.3 - Authenticated (Author+) Stored Cross Site Scripting
high
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version...
- CVSS:
- 8
- Affected:
- 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
- Fixed in:
- 3.7.37
- Disclosed:
- Jan 6, 2022
CVE-2022-21662 on NVD →
WordPress Core < 5.8.3 - SQL Injection via WP_Meta_Query
high
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed...
- CVSS:
- 7.4
- Affected:
- 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
- Fixed in:
- 4.1.34
- Disclosed:
- Jan 6, 2022
CVE-2022-21664 on NVD →
WordPress Core < 5.8.3 - Super Admin Multi-Site Installation Object Injection
medium
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versio...
- CVSS:
- 6.6
- Affected:
- 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
- Fixed in:
- 3.7.37
- Disclosed:
- Jan 6, 2022
CVE-2022-21663 on NVD →
WordPress Core < 5.8 - Dependency Confusion
high
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet...
- CVSS:
- 8.1
- Affected:
- up to 5.7.5
- Fixed in:
- 5.8
- Disclosed:
- Nov 25, 2021
CVE-2021-44223 on NVD →
WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3
medium
WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.
- CVSS:
- 5.3
- Affected:
- up to 5.2, 5.2 – 5.2.12, 5.3 – 5.3.9, 5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
- Fixed in:
- 5.2.13
- Disclosed:
- Nov 10, 2021
WordPress Core 5.4 - 5.8 - Authenticated Stored Cross-Site Scripting
high
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permi...
- CVSS:
- 7.6
- Affected:
- 5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
- Fixed in:
- 5.4.7
- Disclosed:
- Sep 9, 2021
CVE-2021-39201 on NVD →
WordPress Core 5.8 beta - Stored Cross-Site Scripting in Custom HTML Block
high
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This ha...
- CVSS:
- 7.6
- Affected:
- 5.8 beta 1 – 5.8 beta 2
- Fixed in:
- 5.8
- Disclosed:
- Sep 9, 2021
CVE-2021-39202 on NVD →
WordPress Core 5.8 beta - Block Editor Authorization Bypass
medium
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 b...
- CVSS:
- 6.8
- Affected:
- 5.8 beta 1 – 5.8 beta 1
- Fixed in:
- 5.8
- Disclosed:
- Sep 9, 2021
CVE-2021-39203 on NVD →
WordPress Core < 5.8.1 - LoDash Update
medium
WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the LoDash component which is identified as CVE-2020-8203.
- CVSS:
- 6.1
- Affected:
- 5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
- Fixed in:
- 5.4.7
- Disclosed:
- Sep 9, 2021
CVE-2020-8203 on NVD →
WordPress Core 5.4 - 5.8 - Sensitive Information Disclosure
medium
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has...
- CVSS:
- 5.3
- Affected:
- 5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
- Fixed in:
- 5.4.7
- Disclosed:
- Sep 9, 2021
CVE-2021-39200 on NVD →
WordPress Core < 5.7.1 - XXE Injection
high
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPr...
- CVSS:
- 7.1
- Affected:
- 4.7 – 4.7.20, 4.8 – 4.8.16, 4.9 – 4.9.17, 5.0 – 5.0.12, 5.1 – 5.1.9, 5.2 – 5.2.10, 5.3 – 5.3.7, 5.4 – 5.4.5, 5.5 – 5.5.4, 5.6 – 5.6.3, 5.7 – 5.7.1
- Fixed in:
- 4.7.20
- Disclosed:
- Apr 15, 2021
CVE-2021-29447 on NVD →
WordPress Core < 5.7.1 - Sensitive Information Disclosure
medium
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommen...
- CVSS:
- 6.5
- Affected:
- 4.7 – 4.7.20, 4.8 – 4.8.16, 4.9 – 4.9.17, 5.0 – 5.0.12, 5.1 – 5.1.9, 5.2 – 5.2.10, 5.3 – 5.3.7, 5.4 – 5.4.5, 5.5 – 5.5.4, 5.6 – 5.6.3, 5.7 – 5.7.1
- Fixed in:
- 4.7.20
- Disclosed:
- Apr 15, 2021
CVE-2021-29450 on NVD →
WordPress Core < 5.8.3 - SQL Injection via WP_Query
high
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older af...
- CVSS:
- 8
- Affected:
- 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
- Fixed in:
- 3.7.37
- Disclosed:
- Jan 6, 2021
CVE-2022-21661 on NVD →
WordPress Core < 5.5.3 - PHP Object Injection Gadget
critical
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
- CVSS:
- 9.8
- Affected:
- up to 3.7, 3.7 – 3.7.35, 3.8 – 3.8.35, 3.9 – 3.9.33, 4.0 – 4.0.32, 4.1 – 4.1.32, 4.2 – 4.2.29, 4.3 – 4.3.25, 4.4 – 4.4.24, 4.5 – 4.5.23, 4.6 – 4.6.20, 4.7 – 4.7.19, 4.8 – 4.8.15, 4.9 – 4.9.16, 5.0 – 5.0.11, 5.1 – 5.1.8, 5.2 – 5.2.9, 5.3 – 5.3.6, 5.4 – 5.4.4, 5.5 – 5.5.3
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2021-29476 on NVD →
WordPress Core < 5.5.2 - Privilege Escalation via XML-RPC
high
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28036 on NVD →
WordPress Core < 5.5.2 - Deserialization Gadget
high
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28032 on NVD →
WordPress Core < 5.5.2 - Privilege Escalation via XML-RPC
high
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28035 on NVD →
WordPress Core < 5.5.2 - Stored Cross-Site Scripting via post slugs
medium
WordPress before 5.5.2 allows stored XSS via post slugs.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28038 on NVD →
WordPress Core < 5.5.2 - Reflected Cross-Site Scripting via Global Variables
medium
WordPress before 5.5.2 allows XSS associated with global variables.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28034 on NVD →
WordPress Core < 5.5.2 - Arbitrary File Deletion
medium
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28039 on NVD →
WordPress Core < 5.5.2 - Misconfiguration That Allows Trigger of New Installation
medium
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
- CVSS:
- 4.8
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28037 on NVD →
WordPress Core < 5.5.2 - Cross-Site Request Forgery to Theme Image Change
medium
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28040 on NVD →
WordPress Core < 5.5.2 - Spam Embed on Multisite Installations
medium
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
- Fixed in:
- 3.7.35
- Disclosed:
- Oct 29, 2020
CVE-2020-28033 on NVD →
WordPress Core < 5.4.2 - Authenticated Stored Cross-Site Scripting
medium
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in versi...
- CVSS:
- 6.8
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-4047 on NVD →
WordPress Core < 5.4.2 - Open Redirect
medium
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6,...
- CVSS:
- 5.7
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-4048 on NVD →
WordPress Core < 5.4.2 - Authenticated Stored Cross-Site Scripting
medium
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin. This has been patch...
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-4046 on NVD →
WordPress Core < 5.4.2 - Comment Disclosure
medium
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-25286 on NVD →
WordPress Core < 5.4.2 - Arbitrary User Meta Update
low
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along...
- CVSS:
- 3.5
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-4050 on NVD →
WordPress Core < 5.4.2 - Self-Cross Site Scripting via Theme Folder Name
low
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the...
- CVSS:
- 2.4
- Affected:
- up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
- Fixed in:
- 3.7.34
- Disclosed:
- Jun 10, 2020
CVE-2020-4049 on NVD →
WordPress Core < 5.4.1 - Authenticated (Author+) Cross-Site Scripting via File Uploads
medium
In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via...
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11026 on NVD →
WordPress Core < 5.4.1 - Cross-Site Scripting in the Block Editor
medium
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a mi...
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11030 on NVD →
WordPress Core < 5.4.1 - Password Reset Link Non-Expiration
medium
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a...
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11027 on NVD →
WordPress Core < 5.4.1 - Reflected Cross Site Scripting
medium
In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4...
- CVSS:
- 5.8
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11029 on NVD →
WordPress Core < 5.4.1 - Authenticated Cross-Site Scripting via Customizer
medium
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5....
- CVSS:
- 5.8
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11025 on NVD →
WordPress Core < 5.4.1 - Private Post Disclosure
medium
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.1...
- CVSS:
- 5.8
- Affected:
- up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
- Fixed in:
- 3.7.33
- Disclosed:
- Apr 29, 2020
CVE-2020-11028 on NVD →
WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting
medium
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
- Fixed in:
- 3.7.32
- Disclosed:
- Dec 13, 2019
CVE-2019-20041 on NVD →
WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting
medium
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
- Fixed in:
- 3.7.32
- Disclosed:
- Dec 13, 2019
CVE-2019-20042 on NVD →
WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting
medium
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
- CVSS:
- 5.8
- Affected:
- up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4
- Fixed in:
- 3.7.32
- Disclosed:
- Dec 13, 2019
CVE-2019-16781 on NVD →
WordPress Core < 5.3.1 - Stored Cross-Site Scripting via Block Editor
medium
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in...
- CVSS:
- 5.8
- Affected:
- up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
- Fixed in:
- 3.7.32
- Disclosed:
- Dec 13, 2019
CVE-2019-16780 on NVD →
WordPress Core < 5.3.1 - Authorization Bypass
medium
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass...
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
- Fixed in:
- 3.7.32
- Disclosed:
- Dec 1, 2019
CVE-2019-20043 on NVD →
WordPress Core < 5.2.4 - Cache Poisoning
high
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
- CVSS:
- 7.3
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17673 on NVD →
WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting
medium
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17672 on NVD →
WordPress Core < 5.2.4 - Type Confusion
medium
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
- CVSS:
- 5.5
- Affected:
- up to 3.6.1, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17675 on NVD →
WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting via Customizer
medium
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17674 on NVD →
WordPress Core < 5.2.4 - Server Side Request Forgery
medium
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17669 on NVD →
WordPress Core < 5.2.4 - Server Side Request Forgery #2
medium
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17670 on NVD →
WordPress Core < 5.2.4 - Authorization Bypass
medium
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
- Fixed in:
- 3.7.31
- Disclosed:
- Oct 14, 2019
CVE-2019-17671 on NVD →
WordPress Core < 5.2.3 - Stored Cross-Site Scripting via Comments
high
WordPress before 5.2.3 allows XSS in stored comments.
- CVSS:
- 7.2
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16218 on NVD →
WordPress Core < 5.2.3 - Cross-Site Scripting via Media Uploads
medium
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16217 on NVD →
WordPress Core < 5.2.3 - Stored Cross-Site Scripting via Comments via URLs
medium
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16222 on NVD →
WordPress Core < 5.2.3 - Reflected Cross-Site Scripting
medium
WordPress before 5.2.3 allows reflected XSS in the dashboard.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16221 on NVD →
WordPress Core < 5.2.3 - Authenticated Cross-Site Scripting via Post Previews
medium
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16223 on NVD →
WordPress Core < 5.2.3 - Reflected Cross-Site Scripting via Shortcode Previews
medium
WordPress before 5.2.3 allows XSS in shortcode previews.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16219 on NVD →
WordPress Core < 5.2.3 - Open Redirect
medium
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect.
- CVSS:
- 4.6
- Affected:
- up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
- Fixed in:
- 3.7.30
- Disclosed:
- Sep 5, 2019
CVE-2019-16220 on NVD →
WordPress Core < 5.1.1 - Cross-Site Request Forgery to Cross-Site Scripting via Comments
critical
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in admi...
- CVSS:
- 9.6
- Affected:
- up to 3.7, 3.7 – 3.7.28, 3.8 – 3.8.28, 3.9 – 3.9.26, 4.0 – 4.0.25, 4.1 – 4.1.25, 4.2 – 4.2.22, 4.3 – 4.3.18, 4.4 – 4.4.17, 4.5 – 4.5.16, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.8, 4.9 – 4.9.9, 5.0 – 5.0.3, 5.1 – 5.1
- Fixed in:
- 3.7.29
- Disclosed:
- Apr 12, 2019
CVE-2019-9787 on NVD →
WordPress Core < 5.0.1 - Remote Code Execution
high
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code i...
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Feb 19, 2019
CVE-2019-8942 on NVD →
WordPress Core <= 5.0.3 - Path Traversal and Local File Inclusion
medium
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.
- CVSS:
- 6.5
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Feb 19, 2019
CVE-2019-8943 on NVD →
WordPress Core < 5.0.1 - PHP Object Injection
high
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20148 on NVD →
WordPress Core < 5.0.1 - Arbitrary File Deletion
high
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
- CVSS:
- 7.7
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20147 on NVD →
WordPress Core < 5.0.1 - Sensitive Information Disclosure
high
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
- CVSS:
- 7.5
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20151 on NVD →
WordPress Core < 5.0.1 - Stored Cross-Site Scripting via File Uploads
medium
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20149 on NVD →
WordPress Core < 5.0.1 - Authenticated Stored Cross-Site Scripting via Comments
medium
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20153 on NVD →
WordPress Core < 5.0.1 Reflected Cross-Site Scripting
medium
In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20150 on NVD →
WordPress Core < 5.0.1 - Authorization Bypass
medium
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Dec 12, 2018
CVE-2018-20152 on NVD →
WordPress Core < 5.0.1 - PHAR Unserialization
high
WordPress Core versions before 5.0.1 contain a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in o...
- CVSS:
- 7.5
- Affected:
- up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
- Fixed in:
- 3.7.28
- Disclosed:
- Sep 6, 2018
CVE-2018-1000773 on NVD →
WordPress Core < 4.9 - Insecure Deserialization
high
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at...
- CVSS:
- 8.8
- Affected:
- up to 4.9
- Fixed in:
- 4.9
- Disclosed:
- Aug 16, 2018
CVE-2017-1000600 on NVD →
WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload
medium
In all current versions of WordPress Core before 6.4.3, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an atta...
- CVSS:
- 6.6
- Affected:
- up to 4.1, 4.1 – 4.1.39, 4.2 – 4.2.36, 4.3 – 4.3.32, 4.4 – 4.4.31, 4.5 – 4.5.30, 4.6 – 4.6.27, 4.7 – 4.7.27, 4.8 – 4.8.23, 4.9 – 4.9.24, 5.0 – 5.0.20, 5.1 – 5.1.17, 5.2 – 5.2.19, 5.3 – 5.3.16, 5.4 – 5.4.14, 5.5 – 5.5.13, 5.6 – 5.6.12, 5.7 – 5.7.10, 5.8 – 5.8.8, 5.9 – 5.9.8, 6.0 – 6.0.6, 6.1 – 6.1.4, 6.2 – 6.2.3, 6.3 – 6.3.2, 6.4 – 6.4.2
- Fixed in:
- 4.1.40
- Disclosed:
- Aug 4, 2018
CVE-2018-14028 on NVD →
WordPress Core < 4.9.7 - Authenticated Arbitrary File Deletion
high
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachm...
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.26, 3.8 – 3.8.26, 3.9 – 3.9.24, 4.0 – 4.0.23, 4.1 – 4.1.23, 4.2 – 4.2.20, 4.3 – 4.3.16, 4.4 – 4.4.15, 4.5 – 4.5.14, 4.6 – 4.6.11, 4.7 – 4.7.10, 4.8 – 4.8.6, 4.9 – 4.9.6
- Fixed in:
- 3.7.27
- Disclosed:
- Jul 5, 2018
CVE-2018-12895 on NVD →
WordPress Core < 4.9.5 - Authenticated Stored Cross-Site Scripting via Generator Tag
medium
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
- Fixed in:
- 3.7.26
- Disclosed:
- Apr 3, 2018
CVE-2018-10102 on NVD →
WordPress Core < 4.9.5 - Open Redirect
medium
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
- Fixed in:
- 3.7.26
- Disclosed:
- Apr 3, 2018
CVE-2018-10100 on NVD →
WordPress Core < 4.9.5 - Security Misconfiguration with URL Hostnames
medium
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
- Fixed in:
- 3.7.26
- Disclosed:
- Apr 3, 2018
CVE-2018-10101 on NVD →
WordPress Core < 5.0 - Denial of Service
high
In WordPress before 5.0, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. It looks like most of the slowness was due to forcing PHP to repea...
- CVSS:
- 7.5
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Feb 5, 2018
CVE-2018-6389 on NVD →
WordPress Core < 4.9.2 - Authenticated Cross-Site Scripting
medium
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
- CVSS:
- 6.4
- Affected:
- up to 3.6.1, 3.7 – 3.7.24, 3.8 – 3.8.24, 3.9 – 3.9.22, 4.0 – 4.0.21, 4.1 – 4.1.21, 4.2 – 4.2.18, 4.3 – 4.3.14, 4.4 – 4.4.13, 4.5 – 4.5.12, 4.6 – 4.6.9, 4.7 – 4.7.8, 4.8 – 4.8.4, 4.9 – 4.9.1
- Fixed in:
- 3.7.25
- Disclosed:
- Jan 16, 2018
CVE-2018-5776 on NVD →
WordPress Core < 4.9.1- Stored Cross-Site Scripting via Language
medium
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
- Fixed in:
- 3.7.24
- Disclosed:
- Nov 29, 2017
CVE-2017-17093 on NVD →
WordPress Core < 4.9.1 - Authenticated Stored Cross-Site Scripting
medium
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
- Fixed in:
- 3.7.24
- Disclosed:
- Nov 29, 2017
CVE-2017-17092 on NVD →
WordPress Core < 4.9.1 - Reflected Cross-Site Scripting
medium
wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
- Fixed in:
- 3.7.24
- Disclosed:
- Nov 29, 2017
CVE-2017-17094 on NVD →
WordPress Core < 4.9.1 - Authorization Bypass
medium
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
- Fixed in:
- 3.7.24
- Disclosed:
- Nov 29, 2017
CVE-2017-17091 on NVD →
WordPress Core < 4.8.3 - SQL Injection due to Double Prepare approach
critical
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
- CVSS:
- 9.8
- Affected:
- up to 3.7, 3.7 – 3.7.22, 3.8 – 3.8.22, 3.9 – 3.9.20, 4.0 – 4.0.19, 4.1 – 4.1.19, 4.2 – 4.2.16, 4.3 – 4.3.12, 4.4 – 4.4.11, 4.5 – 4.5.10, 4.6 – 4.6.7, 4.7 – 4.7.6, 4.8 – 4.8.2
- Fixed in:
- 3.7.23
- Disclosed:
- Oct 31, 2017
CVE-2017-16510 on NVD →
WordPress Core - All Known Versions - Cleartext Storage of wp_signups.activation_key
medium
All known versions of WordPress Core store cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspeci...
- CVSS:
- 5.3
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2017
CVE-2017-14990 on NVD →
WordPress Core < 4.9.1 - Cross-domain Flash injection
medium
WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
- CVSS:
- 4.7
- Affected:
- up to 3.7, 3.7 – 3.7.24, 3.8 – 3.8.24, 3.9 – 3.9.23, 4.0 – 4.0.21, 4.1 – 4.1.21, 4.2 – 4.2.18, 4.3 – 4.3.14, 4.4 – 4.4.13, 4.5 – 4.5.12, 4.6 – 4.6.9, 4.7 – 4.7.8, 4.8 – 4.8.4, 4.9 – 4.9.1
- Fixed in:
- 3.7.25
- Disclosed:
- Oct 10, 2017
CVE-2016-9263 on NVD →
WordPress Core < 4.8.2 - SQL Injection via Mishandled Placeholders
critical
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.
- CVSS:
- 9.8
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14723 on NVD →
WordPress Core < 4.8.2 - Cross-Site Scripting via Shortcodes
medium
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14726 on NVD →
WordPress Core < 4.8.2 - Cross-Site Scripting via Template Name
medium
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14720 on NVD →
WordPress Core < 4.8.2 - Cross-Site Scripting in oEmbed
medium
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14724 on NVD →
WordPress Core < 4.8.2 - Cross-Site Scripting via Javascript: and Data: URLs
medium
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14718 on NVD →
WordPress Core < 4.8.2 - Stored Cross-Site Scripting via Plugin Names
medium
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14721 on NVD →
WordPress Core < 4.8.2 - Directory Traversal via Customizer
medium
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
- CVSS:
- 4.9
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14722 on NVD →
WordPress Core < 4.8.2 - Directory Traversal during unzip
medium
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14719 on NVD →
WordPress Core < 4.8.2 - Open Redirect in Admin Dashboard
low
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- CVSS:
- 3.5
- Affected:
- up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
- Fixed in:
- 3.7.22
- Disclosed:
- Sep 19, 2017
CVE-2017-14725 on NVD →
WordPress Core < 4.7.5 - Cross-Site Request Forgery Filesystem Credential Update
high
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9064 on NVD →
WordPress Core < 4.7.5 - Server-Side Request Forgery
high
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
- CVSS:
- 7.7
- Affected:
- up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9066 on NVD →
WordPress Core < 4.7.5 - Stored Cross-Site Scripting via filenames
medium
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.
- CVSS:
- 6.4
- Affected:
- up to 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9061 on NVD →
WordPress Core < 4.7.5 - Mishandling Post Meta Values via XML-RPC
medium
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
- CVSS:
- 6.3
- Affected:
- up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9062 on NVD →
WordPress Core < 4.7.5 - Cross-Site Scripting via Customizer
medium
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9063 on NVD →
WordPress Core < 4.7.5 - Authorization Bypass Allowing Post Meta Updates
medium
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
- Fixed in:
- 3.7.21
- Disclosed:
- May 16, 2017
CVE-2017-9065 on NVD →
Wordpress Core < 5.5 - Unauthorized Password Reset via Interception
medium
WordPress up to version 5.5 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the...
- CVSS:
- 5.9
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- May 3, 2017
CVE-2017-8295 on NVD →
WordPress Core < 4.7.3 - Cross-Site Request Forgery via Press This
high
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6819 on NVD →
WordPress Core < 4.7.3 - Authenticated Cross-Site Scripting in Youtube URL Embeds
medium
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6817 on NVD →
WordPress Core < 4.7.3 - Cross-Site Scripting via Media Metadata
medium
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/...
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6814 on NVD →
WordPress Core < 4.7.3 - Cross-Site Scripting via Taxonomy names
medium
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6818 on NVD →
WordPress Core < 4.7.3 - Bypass URL Validation
medium
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6815 on NVD →
WordPress Core < 4.7.3 - Arbitrary File Deletion
medium
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
- CVSS:
- 4.9
- Affected:
- up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
- Fixed in:
- 3.7.19
- Disclosed:
- Mar 6, 2017
CVE-2017-6816 on NVD →
WordPress Core < 4.7.2 - Authenticated SQL Injection
high
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
- Fixed in:
- 3.7.18
- Disclosed:
- Jan 26, 2017
CVE-2017-5611 on NVD →
WordPress Core < 4.7.2 - Arbitrary Page Modification
high
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-nu...
- CVSS:
- 7.3
- Affected:
- up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
- Fixed in:
- 3.7.18
- Disclosed:
- Jan 26, 2017
CVE-2017-1001000 on NVD →
WordPress Core < 4.7.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
- Fixed in:
- 3.7.18
- Disclosed:
- Jan 26, 2017
CVE-2017-5612 on NVD →
WordPress Core < 4.7.2 - Authorization Bypass to Term Disclosure
medium
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
- Fixed in:
- 3.7.18
- Disclosed:
- Jan 26, 2017
CVE-2017-5610 on NVD →
WordPress Core < 4.7.1 - Cross-Site Request Forgery via Widget Editing
high
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets....
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5492 on NVD →
WordPress Core < 4.7.1 - Cross-Site Request Forgery via Uploading Flash File
high
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5489 on NVD →
WordPress Core < 4.7.1 - Authorization Bypass
high
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
- CVSS:
- 8.3
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5491 on NVD →
WordPress Core < 4.7.1 - Stored Cross-Site Scripting via theme directory name
medium
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5490 on NVD →
WordPress Core < 4.7.1 - Cross-Site Scripting via Name and Version Header of Plugin
medium
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5488 on NVD →
WordPress Core < 4.7.1 - Weak Multi-Site Activation Key for User and Site Signup
medium
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5493 on NVD →
WordPress Core < 4.7.1 - Information Disclosure
medium
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7
- Fixed in:
- 3.7.17
- Disclosed:
- Jan 11, 2017
CVE-2017-5487 on NVD →
WordPress Core < 4.7.2 - Path Disclosure
medium
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
- Fixed in:
- 3.7.18
- Disclosed:
- Jan 1, 2017
CVE-2017-6514 on NVD →
WordPress Core < 4.5 - Server-Side Request Forgery
medium
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
- CVSS:
- 5
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Sep 29, 2016
CVE-2016-4029 on NVD →
WordPress Core < 4.6.1 - Authenticated Directory Traversal to Arbitrary File Access
medium
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
- CVSS:
- 6.5
- Affected:
- up to 3.7, 3.7 – 3.7.15, 3.8 – 3.8.15, 3.9 – 3.9.13, 4.0 – 4.0.12, 4.1 – 4.1.12, 4.2 – 4.2.9, 4.3 – 4.3.5, 4.4 – 4.4.4, 4.5 – 4.5.3, 4.6 – 4.6
- Fixed in:
- 3.7.16
- Disclosed:
- Sep 7, 2016
CVE-2016-7169 on NVD →
WordPress Core < 4.6.1 - Authenticated Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
- CVSS:
- 4.8
- Affected:
- up to 3.7, 3.7 – 3.7.15, 3.8 – 3.8.15, 3.9 – 3.9.13, 4.0 – 4.0.12, 4.1 – 4.1.12, 4.2 – 4.2.9, 4.3 – 4.3.5, 4.4 – 4.4.4, 4.5 – 4.5.3, 4.6 – 4.6
- Fixed in:
- 3.7.16
- Disclosed:
- Sep 7, 2016
CVE-2016-7168 on NVD →
WordPress Core <= 4.5.3 - Denial of Service
medium
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random...
- CVSS:
- 6.5
- Affected:
- up to 4.6
- Fixed in:
- 4.6
- Disclosed:
- Aug 22, 2016
CVE-2016-6896 on NVD →
WordPress Core < 4.6 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related...
- CVSS:
- 8.8
- Affected:
- up to 4.6
- Fixed in:
- 4.6
- Disclosed:
- Aug 16, 2016
CVE-2016-6897 on NVD →
WordPress Core < 4.6 - Authorization Bypass
medium
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related...
- CVSS:
- 4.3
- Affected:
- up to 4.6
- Fixed in:
- 4.6
- Disclosed:
- Aug 16, 2016
CVE-2016-10148 on NVD →
WordPress Core < 4.5.3 - Bypass sanitize_file_name Protection
high
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
- CVSS:
- 7.3
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5839 on NVD →
WordPress Core < 4.5.3 - Cross-Site Scripting via Attachment Name
medium
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5834 on NVD →
WordPress Core < 4.5.3 - Cross-Site Scripting via Attachment Name #2
medium
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5833 on NVD →
WordPress Core < 4.5.3 - Cross-Site Scripting via Customizer
medium
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5832 on NVD →
WordPress Core < 4.5.3 - Authorization Bypass to Remove Category Attribute
medium
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5837 on NVD →
WordPress Core < 4.5.3 - Denial of Service via oEmbed Protocol
medium
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5836 on NVD →
WordPress Core < 4.5.3 - Password Change via Stolen Cookie
medium
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5838 on NVD →
WordPress Core < 4.5.3 - Revision History Disclosure
medium
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
- Fixed in:
- 3.7.15
- Disclosed:
- Jun 18, 2016
CVE-2016-5835 on NVD →
WordPress Core < 4.5.2 - Cross-Site Scripting via MediaElement.js
medium
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.13, 3.8 – 3.8.13, 3.9 – 3.9.11, 4.0 – 4.0.10, 4.1 – 4.1.10, 4.2 – 4.2.7, 4.3 – 4.3.3, 4.4 – 4.4.2, 4.5 – 4.5.1
- Fixed in:
- 3.7.14
- Disclosed:
- May 6, 2016
CVE-2016-4567 on NVD →
WordPress Core < 4.5.2 - Cross-Site Scripting via plupload.flash.swf
medium
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.13, 3.8 – 3.8.13, 3.9 – 3.9.11, 4.0 – 4.0.10, 4.1 – 4.1.10, 4.2 – 4.2.7, 4.3 – 4.3.3, 4.4 – 4.4.2, 4.5 – 4.5.1
- Fixed in:
- 3.7.14
- Disclosed:
- May 6, 2016
CVE-2016-4566 on NVD →
WordPress Core < 4.5 - Cross-Site Scripting via Network Settings Page
medium
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Apr 12, 2016
CVE-2016-6634 on NVD →
WordPress Core < 4.5 - Cross-Site Request Forgery via wp_ajax_wp_compression_test
high
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
- CVSS:
- 8.8
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Mar 12, 2016
CVE-2016-6635 on NVD →
WordPress Core < 4.4.2 - Server-Side Request Forgery
medium
The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.12, 3.8 – 3.8.12, 3.9 – 3.9.10, 4.0 – 4.0.9, 4.1 – 4.1.9, 4.2 – 4.2.6, 4.3 – 4.3.2, 4.4 – 4.4.1
- Fixed in:
- 3.7.13
- Disclosed:
- Feb 2, 2016
CVE-2016-2222 on NVD →
WordPress Core < 4.4.2 - Open Redirect via wp_validate_redirect
medium
Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.12, 3.8 – 3.8.12, 3.9 – 3.9.10, 4.0 – 4.0.9, 4.1 – 4.1.9, 4.2 – 4.2.6, 4.3 – 4.3.2, 4.4 – 4.4.1
- Fixed in:
- 3.7.13
- Disclosed:
- Feb 2, 2016
CVE-2016-2221 on NVD →
WordPress Core < 4.4.1 - Cross-Site Scripting via Theme Names
medium
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.11, 3.8 – 3.8.11, 3.9 – 3.9.9, 4.0 – 4.0.8, 4.1 – 4.1.8, 4.2 – 4.2.5, 4.3 – 4.3.1, 4.4 – 4.4
- Fixed in:
- 3.7.12
- Disclosed:
- Jan 16, 2016
CVE-2016-1564 on NVD →
WordPress Core < 4.3.1 - Authenticated Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
- Fixed in:
- 3.7.11
- Disclosed:
- Sep 15, 2015
CVE-2015-7989 on NVD →
WordPress Core < 4.3.1 - Cross-Site Scripting via Shortcodes
medium
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
- Fixed in:
- 3.7.11
- Disclosed:
- Sep 15, 2015
CVE-2015-5714 on NVD →
WordPress Core < 4.3.1 - Authorization Bypass to Information Disclosure
medium
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
- Fixed in:
- 3.7.11
- Disclosed:
- Sep 15, 2015
CVE-2015-5715 on NVD →
WordPress Core < 4.2.4 - Cross-Site Request Forgery to Post Lockage
critical
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.
- CVSS:
- 9.6
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-5731 on NVD →
WordPress Core < 4.2.4 - SQL Injection
high
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-2213 on NVD →
WordPress Core < 4.2.4 - Cross-Site Scripting in Theme Preview
medium
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
- CVSS:
- 6.1
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-5734 on NVD →
WordPress Core < 4.2.4 - Cross-Site Scripting via Widget Title
medium
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
- CVSS:
- 5.5
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-5732 on NVD →
WordPress Core < 4.2.4 - Stored Cross-Site Scripting via accessibility-helper Title
medium
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-5733 on NVD →
WordPress Core < 4.2.4 - Timing Side-Channel Attack
medium
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
- Fixed in:
- 3.7.10
- Disclosed:
- Aug 4, 2015
CVE-2015-5730 on NVD →
WordPress Core < 4.2.3 - Authorization Bypass
medium
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
- CVSS:
- 6.5
- Affected:
- up to 3.7, 3.7 – 3.7.8, 3.8 – 3.8.8, 3.9 – 3.9.6, 4.0 – 4.0.5, 4.1 – 4.1.5, 4.2 – 4.2.2
- Fixed in:
- 3.7.9
- Disclosed:
- Jul 23, 2015
CVE-2015-5623 on NVD →
WordPress Core < 4.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.8, 3.8 – 3.8.8, 3.9 – 3.9.6, 4.0 – 4.0.5, 4.1 – 4.1.5, 4.2 – 4.2.2
- Fixed in:
- 3.7.9
- Disclosed:
- Jul 23, 2015
CVE-2015-5622 on NVD →
WordPress Core < 4.2.2 - Cross-Site Scripting via Comments
high
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CV...
- CVSS:
- 7.2
- Affected:
- up to 3.7, 3.7 – 3.7.7, 3.8 – 3.8.7, 3.9 – 3.9.5, 4.0 – 4.0.4, 4.1 – 4.1.4, 4.2 – 4.2.1
- Fixed in:
- 3.7.8
- Disclosed:
- May 7, 2015
CVE-2015-8834 on NVD →
WordPress Core < 4.2.1 - Cross-Site Scripting via Comments
high
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
- CVSS:
- 7.2
- Affected:
- 4.0 – 4.0.3, 4.1 – 4.1.3, 4.2 – 4.2
- Fixed in:
- 4.0.4
- Disclosed:
- Apr 27, 2015
CVE-2015-3440 on NVD →
WordPress Core < 4.1.2 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a c...
- CVSS:
- 7.2
- Affected:
- up to 3.7, 3.7 – 3.7.5, 3.8 – 3.8.5, 3.9 – 3.9.3, 4.0 – 4.0.1, 4.1 – 4.1.1
- Fixed in:
- 3.7.6
- Disclosed:
- Apr 21, 2015
CVE-2015-3438 on NVD →
WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload
medium
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a...
- CVSS:
- 5.4
- Affected:
- up to 3.7, 3.7 – 3.7.5, 3.8 – 3.8.5, 3.9 – 3.9.3, 4.0 – 4.0.1, 4.1 – 4.1.1
- Fixed in:
- 3.7.6
- Disclosed:
- Apr 20, 2015
CVE-2015-3439 on NVD →
Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html
medium
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.7, 3.8 – 3.8.7, 3.9 – 3.9.5, 4.0 – 4.0.4, 4.1 – 4.1.4, 4.2 – 4.2.1
- Fixed in:
- 3.7.8
- Disclosed:
- Apr 8, 2015
CVE-2015-3429 on NVD →
WordPress Core < 4.4 - Brute Force Password Recovery Tokens
high
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- CVSS:
- 7.5
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Feb 12, 2015
CVE-2014-6412 on NVD →
WordPress Core < 4.0.1 Cross-Site Request Forgery to Password Reset
high
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9039 on NVD →
Wordpress Core < 4.0.1 - Hash Collision
high
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
- CVSS:
- 8.1
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9037 on NVD →
WordPress Core < 4.0.1 - Server-Side Request Forgery
high
wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.
- CVSS:
- 7.7
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9038 on NVD →
WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists
high
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 7.2
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9032 on NVD →
WordPress Core < 4.0.1 - Cross-Site Scripting via CSS
medium
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.
- CVSS:
- 6.4
- Affected:
- up to 3.6.1, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9036 on NVD →
WordPress Core < 4.0.1 - Cross-Site Scripting via Shortcode Brackets
medium
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9031 on NVD →
WordPress Core < 4.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9035 on NVD →
WordPress Core < 4.0.1 - Denial of Service via Long Password
medium
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
- CVSS:
- 5.3
- Affected:
- up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 20, 2014
CVE-2014-9034 on NVD →
WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass
high
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5204 on NVD →
WordPress Core < 4.0.1 - Cross-Site Request Forgery to Authentication Takeover
high
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.
- CVSS:
- 8.8
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-9033 on NVD →
WordPress Core < 3.9.2 - Deserialization via Widgets
high
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
- CVSS:
- 7.2
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5203 on NVD →
WordPress Core < 3.9.2 - Brute Force of Cross-Site Request Forgery Tokens
medium
wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
- CVSS:
- 6.5
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5205 on NVD →
WordPress Core < 3.9.2 - Denial of Service via XML #2
medium
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
- CVSS:
- 6.5
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5266 on NVD →
WordPress Core <= 3.9.1 - XML External Entity (XXE) Weakness
medium
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
- CVSS:
- 5.3
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Aug 6, 2014
CVE-2014-2053 on NVD →
WordPress Core < 3.9.2 - Authenticated Cross-Site Scripting via Avatar URL
low
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
- CVSS:
- 3.8
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5240 on NVD →
WordPress Core < 3.9.2 - Denial of Service via XML
low
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document conta...
- CVSS:
- 2.7
- Affected:
- up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
- Fixed in:
- 3.7.4
- Disclosed:
- Aug 6, 2014
CVE-2014-5265 on NVD →
WordPress Core < 3.8.2 - SQL Injection
high
WordPress Core, in versions less than 3.8.2, is vulnerable to SQL Injection via the 'links_recently_updated_time' parameter. This can only be exploited by administrative users and above.
- CVSS:
- 7.2
- Affected:
- 3.8.1 – 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- Apr 9, 2014
WordPress Core < 3.8.2 - Authentication Cookie Forgery
medium
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.
- CVSS:
- 6.5
- Affected:
- up to 3.7, 3.7 – 3.7.1, 3.8 – 3.8.1
- Fixed in:
- 3.7.2
- Disclosed:
- Apr 8, 2014
CVE-2014-0166 on NVD →
WordPress Core < 3.8.2 - Contributor Users Can Publish Posts
medium
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.
- CVSS:
- 4.3
- Affected:
- up to 3.7, 3.7 – 3.7.1, 3.8 – 3.8.1
- Fixed in:
- 3.7.2
- Disclosed:
- Apr 8, 2014
CVE-2014-0165 on NVD →
WordPress Core < 2.1 - Cross-Site Request Forgery to Denial of Service
high
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.
- CVSS:
- 8.8
- Affected:
- up to 2.0.11
- Fixed in:
- 2.1
- Disclosed:
- Dec 17, 2013
CVE-2013-7233 on NVD →
WordPress Core < 3.6.1 - Deserialization
high
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
- CVSS:
- 8.8
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 11, 2013
CVE-2013-4338 on NVD →
WordPress Core < 3.6.1 - HTML File Upload
medium
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.
- CVSS:
- 6.4
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 11, 2013
CVE-2013-5738 on NVD →
WordPress Core < 3.6.1 - .swf and .exe File Upload
medium
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
- CVSS:
- 6.4
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 11, 2013
CVE-2013-5739 on NVD →
WordPress Core < 3.6.1 - Spoof Post Authorship
medium
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
- CVSS:
- 6.3
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 11, 2013
CVE-2013-4340 on NVD →
WordPress Core < 3.6.1 - Open Redirect
medium
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
- CVSS:
- 5.4
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 11, 2013
CVE-2013-4339 on NVD →
WordPress Core < 3.5.2 - Cross-Site Scripting via Multiple Vectors
medium
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to the...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2201 on NVD →
WordPress Core < 3.5.2 - Cross-Site Scripting
medium
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
- CVSS:
- 6.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2205 on NVD →
WordPress Core < 3.5.2 - Missing Authorization Checks
medium
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.
- CVSS:
- 6.3
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2200 on NVD →
WordPress Core < 3.5.2 - XXE Injection
medium
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVSS:
- 5.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2202 on NVD →
WordPress Core < 3.5.2 - Server Side Request Forgery
medium
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
- CVSS:
- 5.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2199 on NVD →
WordPress Core <= 3.5.1 - Denial of Service via wp-postpass cookie
medium
wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.
- CVSS:
- 5.3
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2173 on NVD →
WordPress Core <= 3.5.1 - Content-Spoofing Attacks
medium
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct co...
- CVSS:
- 4.6
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2204 on NVD →
WordPress Core < 3.5.2 - Sensitive Information Disclosure
medium
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
- CVSS:
- 4.3
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 21, 2013
CVE-2013-2203 on NVD →
WordPress Core < 3.5.1 - Stored Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
- CVSS:
- 6.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- Jan 24, 2013
CVE-2013-0236 on NVD →
WordPress Core < 3.5.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- CVSS:
- 6.4
- Affected:
- up to 3.5
- Fixed in:
- 3.5.1
- Disclosed:
- Jan 24, 2013
CVE-2013-0237 on NVD →
WordPress Core < 3.5.1 - Server-Side Request Forgery
medium
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
- CVSS:
- 5.4
- Affected:
- up to 3.5
- Fixed in:
- 3.5.1
- Disclosed:
- Jan 24, 2013
CVE-2013-0235 on NVD →
WordPress Core < 4.0 - Missing Session Cookie Expiration
medium
WordPress Core before 4.0 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.
- CVSS:
- 5.4
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Dec 27, 2012
CVE-2012-5868 on NVD →
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
WordPress Core < 3.4.2 - Cross-Site Scripting
medium
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leve...
- CVSS:
- 6.4
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 6, 2012
CVE-2012-3383 on NVD →
WordPress Core < 3.4.2 - Missing Authorization Checks on create_post
medium
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) fea...
- CVSS:
- 6.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 6, 2012
CVE-2012-4421 on NVD →
WordPress Core < 3.4.2 - Missing Authorization Checks
low
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator ro...
- CVSS:
- 3.8
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 6, 2012
CVE-2012-4422 on NVD →
WordPress Core < 3.4.1 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVSS:
- 8.8
- Affected:
- up to 3.4
- Fixed in:
- 3.4.1
- Disclosed:
- Jun 27, 2012
CVE-2012-3384 on NVD →
WordPress Core <= 3.3.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
- CVSS:
- 6.5
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Jun 27, 2012
CVE-2012-6633 on NVD →
WordPress Core <= 3.3.2 - Sensitive Information Disclosure
medium
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
- CVSS:
- 5.3
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Jun 27, 2012
CVE-2012-6634 on NVD →
WordPress Core <= 3.3.2 - Sensitive Information Disclosure
medium
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
- CVSS:
- 4.3
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Jun 27, 2012
CVE-2012-6635 on NVD →
WordPress Core < 3.4.1 - Information Disclosure
medium
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
- CVSS:
- 4.3
- Affected:
- up to 3.4
- Fixed in:
- 3.4.1
- Disclosed:
- Jun 27, 2012
CVE-2012-3385 on NVD →
WordPress Core - Informational < 6.8 - Weak Hashing Algorithm
low
Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a Wor...
- CVSS:
- 3.7
- Affected:
- up to 6.8
- Fixed in:
- 6.8
- Disclosed:
- Jun 20, 2012
CVE-2012-6707 on NVD →
WordPress Core <= 3.5.1 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-34...
- CVSS:
- 7.2
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Apr 21, 2012
CVE-2012-2399 on NVD →
WordPress Core <= 3.3.1 - Cross-Site Scripting
medium
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 21, 2012
CVE-2012-2404 on NVD →
WordPress Core < 3.3.2 - Cross-Site Scripting
high
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
- CVSS:
- 7.2
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 20, 2012
CVE-2012-2400 on NVD →
WordPress Core <= 3.3.1 - Same Origin Policy Bypass
medium
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
- CVSS:
- 6.5
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 20, 2012
CVE-2012-2401 on NVD →
WordPress Core < 3.3.2 - Cross-Site Scripting
medium
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 20, 2012
CVE-2012-2403 on NVD →
WordPress Core <= 3.3.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 5.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 20, 2012
CVE-2012-3414 on NVD →
WordPress Core < 3.3.2 - Authorization Bypass
medium
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Apr 20, 2012
CVE-2012-2402 on NVD →
WordPress Core <= 3.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
- CVSS:
- 6.4
- Affected:
- up to 3.3
- Fixed in:
- 3.3.1
- Disclosed:
- Jan 3, 2012
CVE-2012-0287 on NVD →
WordPress Core <= 3.1.2 - Arbitrary File Upload
high
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
- CVSS:
- 8.8
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3129 on NVD →
WordPress Core <= 3.1.2 - SQL Injection
high
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.
- CVSS:
- 8.8
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3130 on NVD →
WordPress Core < 3.1.3 - Clickjacking
high
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
- CVSS:
- 7.1
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3127 on NVD →
WordPress Core < 3.1.3 - Media Related Security Issue
medium
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."
- CVSS:
- 6.3
- Affected:
- up to 3.1.2
- Fixed in:
- 3.2
- Disclosed:
- May 25, 2011
CVE-2011-3122 on NVD →
WordPress Core < 3.1.3 - Security Hardening
medium
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."
- CVSS:
- 6.3
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3125 on NVD →
WordPress Core < 3.1.3 - Username Enumeration
medium
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
- CVSS:
- 5.3
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3126 on NVD →
WordPress Core < 3.1.3 - Sensitive Information Disclosure
medium
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.
- CVSS:
- 4.3
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 25, 2011
CVE-2011-3128 on NVD →
WordPress Core < 3.0.6 - Incorrect Authorization Checks
medium
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
- CVSS:
- 6.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Apr 26, 2011
CVE-2011-5270 on NVD →
WordPress Core < 3.1.2 - Incorrect Authorization for Contributor-level users
medium
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
- CVSS:
- 4.3
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Apr 26, 2011
CVE-2011-1762 on NVD →
WordPress Core < 3.1.1 - Denial of Service
high
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.
- CVSS:
- 7.5
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 5, 2011
CVE-2011-4957 on NVD →
WordPress Core <= 3.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 3.1
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 5, 2011
CVE-2011-4956 on NVD →
WordPress Core < 3.0.5 - Improper Authorization to Information Disclosure
medium
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
- CVSS:
- 4.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Feb 7, 2011
CVE-2011-0701 on NVD →
WordPress Core 2.9.2 and 3.0.4 - Sensitive Information Disclosure
high
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.
- CVSS:
- 7.5
- Affected:
- 2.9.2 – 2.9.2, 3.0.4 – 3.0.4
- Fixed in:
- 3.0
- Disclosed:
- Jan 28, 2011
CVE-2011-3818 on NVD →
WordPress Core < 3.0.2 - Missing Authorization
medium
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
- CVSS:
- 5.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Dec 30, 2010
CVE-2010-5296 on NVD →
WordPress Core <= 3.0.3 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
- CVSS:
- 6.4
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Dec 29, 2010
CVE-2010-4536 on NVD →
WordPress Core < 3.0.3 - Access Control Bypass
medium
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
- CVSS:
- 6.3
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Dec 8, 2010
CVE-2010-5106 on NVD →
WordPress Core <= 3.0.1 - SQL Injection
high
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.
- CVSS:
- 8.8
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Nov 30, 2010
CVE-2010-4257 on NVD →
WordPress Core < 3.0.2 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
- CVSS:
- 6.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Nov 30, 2010
CVE-2010-5294 on NVD →
WordPress Core < 3.0.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
- CVSS:
- 6.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Nov 30, 2010
CVE-2010-5295 on NVD →
WordPress Core < 3.0.2 - Spam Protection Bypass
medium
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
- CVSS:
- 5.3
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Nov 30, 2010
CVE-2010-5293 on NVD →
WordPress Core < 3.0.1 - Missing Authorization
medium
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
- CVSS:
- 4.7
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Jul 29, 2010
CVE-2010-5297 on NVD →
WordPress Core < 2.9.2 - Authorization Bypass
medium
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
- CVSS:
- 4.3
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Feb 15, 2010
CVE-2010-0682 on NVD →
WordPress Core <= 2.8.5 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-...
- CVSS:
- 8.8
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.6
- Disclosed:
- Dec 12, 2009
CVE-2009-3890 on NVD →
WordPress Core <= 2.8.5 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
- CVSS:
- 6.4
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.6
- Disclosed:
- Dec 12, 2009
CVE-2009-3891 on NVD →
WordPress Core <= 2.8.4 - Denial of Service
medium
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_enco...
- CVSS:
- 6.5
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Oct 20, 2009
CVE-2009-3622 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Full Path Disclosure
medium
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Sep 8, 2009
CVE-2009-2432 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Full Path Disclosure
medium
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Sep 8, 2009
CVE-2009-2432 on NVD →
WordPress Core < 2.8.4 - Forced Password Reset
high
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
- CVSS:
- 7.5
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Aug 12, 2009
CVE-2009-2762 on NVD →
WordPress Core < 2.8.3 - Missing Authorization
high
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.ph...
- CVSS:
- 7.3
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.3
- Disclosed:
- Aug 3, 2009
CVE-2009-2854 on NVD →
WordPress Core < 2.8.3 - Authorization Bypass
high
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
- CVSS:
- 7.3
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.3
- Disclosed:
- Aug 3, 2009
CVE-2009-2853 on NVD →
WordPress Core <= 2.8.1 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
- CVSS:
- 7.2
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Jul 20, 2009
CVE-2009-2851 on NVD →
WordPress Core <= 2.8 - Sensitive Information Disclosure
medium
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collap...
- CVSS:
- 6.1
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2334 on NVD →
WordPress Core <= 2.8 - Sensitive Information Disclosure
medium
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collap...
- CVSS:
- 6.1
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2334 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Username Enumeration
medium
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user conv...
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2335 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Username Enumeration
medium
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the b...
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2336 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Username Enumeration
medium
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the b...
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2336 on NVD →
WordPress Core & WordPress MU < 2.8.1 - Username Enumeration
medium
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user conv...
- CVSS:
- 5.3
- Affected:
- up to 2.8
- Fixed in:
- 2.8.1
- Disclosed:
- Jul 9, 2009
CVE-2009-2335 on NVD →
WordPress Core < 2.8 - Sensitive Information Disclosure
medium
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
- CVSS:
- 5.3
- Affected:
- up to 2.7.1
- Fixed in:
- 2.8
- Disclosed:
- Jun 11, 2009
CVE-2009-2431 on NVD →
WordPress MU < 2.7 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
- CVSS:
- 6.4
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Mar 10, 2009
CVE-2009-1030 on NVD →
WordPress Core < 2.6.5 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
- CVSS:
- 7.2
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.5
- Disclosed:
- Dec 25, 2008
CVE-2008-5278 on NVD →
WordPress Core < 2.8.1 - Open Redirect
medium
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.1
- Disclosed:
- Dec 22, 2008
CVE-2008-6762 on NVD →
WordPress Core < 2.7 - Denial of Service
medium
wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request if WordPress is not yet setup by creating an empty database, which will prevent future installations from succeeding.
- CVSS:
- 5.3
- Affected:
- up to 2.6.1
- Fixed in:
- 2.7
- Disclosed:
- Dec 22, 2008
CVE-2008-6767 on NVD →
WordPress Core < 2.6.2 - Arbitrary User Password Reset
high
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value...
- CVSS:
- 8.1
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Sep 8, 2008
CVE-2008-4106 on NVD →
WordPress Core < 2.6.2 - Cryptographic Weakness
medium
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before...
- CVSS:
- 6.5
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Sep 8, 2008
CVE-2008-4107 on NVD →
WordPress MU < 2.6 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.
- CVSS:
- 6.4
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Sep 1, 2008
CVE-2008-4671 on NVD →
WordPress Core < 2.6.1 - Cryptographic Weakness
medium
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
- CVSS:
- 5.9
- Affected:
- up to 2.6
- Fixed in:
- 2.6.1
- Disclosed:
- Aug 15, 2008
CVE-2008-3747 on NVD →
WordPress Core < 2.6 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 7.2
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jul 15, 2008
CVE-2008-3233 on NVD →
WordPress Core < 2.5.1 - Authentication Bypass
high
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtai...
- CVSS:
- 8.1
- Affected:
- up to 2.5
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 25, 2008
CVE-2008-1930 on NVD →
WordPress Core <= 2.3.3 - Directory Traversal
high
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information...
- CVSS:
- 7.5
- Affected:
- up to 2.3.3, 2.5 – 2.5
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 25, 2008
CVE-2008-4769 on NVD →
WordPress Core <= 2.5.1 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.
- CVSS:
- 7.2
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Apr 25, 2008
CVE-2008-2392 on NVD →
WordPress Core <= 2.5 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 2.5
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 25, 2008
CVE-2008-2068 on NVD →
WordPress Core <= 2.3.2 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
- CVSS:
- 6.4
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Feb 5, 2008
CVE-2008-1304 on NVD →
WordPress Core 1.5 - 2.3.1 - Authorization Bypass
critical
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
- CVSS:
- 9.8
- Affected:
- 1.5 – 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Dec 29, 2007
CVE-2007-6013 on NVD →
WordPress Core < 2.5 - Full Path Disclosure
medium
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
- CVSS:
- 5.3
- Affected:
- up to 2.4
- Fixed in:
- 2.5
- Disclosed:
- Dec 16, 2007
CVE-2008-0191 on NVD →
WordPress Core <= 2.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
- CVSS:
- 6.4
- Affected:
- up to 2.3
- Fixed in:
- 2.3.1
- Disclosed:
- Oct 26, 2007
CVE-2007-5710 on NVD →
WordPress Core < 2.0.4 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.
- CVSS:
- 6.4
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Sep 21, 2007
CVE-2007-5106 on NVD →
WordPress Core < 2.3.2 - SQL Injection
critical
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.
- CVSS:
- 9.8
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Sep 8, 2007
CVE-2007-6318 on NVD →
WordPress Core < 2.2.3 & WordPress MU < 1.2.5a - SQL Injection
critical
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early dat...
- CVSS:
- 9.8
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Sep 8, 2007
CVE-2007-4894 on NVD →
WordPress Core < 2.2.3 & WordPress MU < 1.2.5a - SQL Injection
critical
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early dat...
- CVSS:
- 9.8
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Sep 8, 2007
CVE-2007-4894 on NVD →
WordPress Core < 2.3.3 & WordPress MU < 1.3.2 - Remote Code Execution
high
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to...
- CVSS:
- 8.8
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Sep 8, 2007
CVE-2008-5695 on NVD →
WordPress Core < 2.3.3 & WordPress MU < 1.3.2 - Remote Code Execution
high
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to...
- CVSS:
- 8.8
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Sep 8, 2007
CVE-2008-5695 on NVD →
WordPress Core < 2.3.3 - Improper Authorization Checks
medium
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.
- CVSS:
- 6.5
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Sep 8, 2007
CVE-2008-0664 on NVD →
WordPress Core < 2.2.3 - Restriction Bypass
medium
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
- CVSS:
- 5.3
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Sep 8, 2007
CVE-2008-2146 on NVD →
WordPress MU <= 1.0 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Aug 22, 2007
CVE-2007-4544 on NVD →
WordPress Core < 2.2.2 - Open Redirect
medium
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.p...
- CVSS:
- 6.1
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Aug 8, 2007
CVE-2007-3639 on NVD →
WordPress Core <= 2.2.1 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts....
- CVSS:
- 8.8
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Aug 5, 2007
CVE-2007-3544 on NVD →
WordPress Core <= 2.2 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID...
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 5, 2007
CVE-2007-3543 on NVD →
WordPress Core <= 2.2.1 - SQL Injection
high
SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permali...
- CVSS:
- 8.8
- Affected:
- up to 2.0.10, 2.2 – 2.2.1
- Fixed in:
- 2.0.11
- Disclosed:
- Aug 5, 2007
CVE-2007-4154 on NVD →
WordPress Core <= 2.2.1 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts....
- CVSS:
- 8.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Aug 5, 2007
CVE-2007-3544 on NVD →
WordPress Core <= 2.2.2 - Cross-Site Scripting
medium
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
- CVSS:
- 6.4
- Affected:
- up to 1.2.5a
- Fixed in:
- 1.2.5a
- Disclosed:
- Aug 5, 2007
CVE-2007-4893 on NVD →
WordPress Core <= 2.2.2 - Cross-Site Scripting
medium
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
- CVSS:
- 6.4
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Aug 5, 2007
CVE-2007-4893 on NVD →
WordPress Core <= 2.2.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php.
- CVSS:
- 6.4
- Affected:
- up to 2.0.10, 2.2 – 2.2.1
- Fixed in:
- 2.0.11
- Disclosed:
- Aug 5, 2007
CVE-2007-4139 on NVD →
WordPress Core <= 2.2.1 - Authenticated (Admin+) Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privi...
- CVSS:
- 5.5
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Aug 5, 2007
CVE-2007-4153 on NVD →
WordPress Core <= 2.2 - SQL Injection
high
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 21, 2007
CVE-2007-3140 on NVD →
WordPress Core <= 2.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.
- CVSS:
- 6.1
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 21, 2007
CVE-2007-2627 on NVD →
WordPress Core < 2.1.3 - SQL Injection
high
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.
- CVSS:
- 8.8
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Apr 3, 2007
CVE-2007-1897 on NVD →
WordPress Core <= 2.0.9 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.
- CVSS:
- 7.2
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 3, 2007
CVE-2008-0192 on NVD →
WordPress Core <= 2.1.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.
- CVSS:
- 6.4
- Affected:
- up to 2.0.9, 2.1 – 2.1.2
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 3, 2007
CVE-2007-1894 on NVD →
WordPress Core < 2.0.10 - Open Redirect
medium
wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 3, 2007
CVE-2007-1599 on NVD →
WordPress Core <= 2.1.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression proc...
- CVSS:
- 6.1
- Affected:
- up to 2.0.9, 2.1 – 2.1.1
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 3, 2007
CVE-2007-1622 on NVD →
WordPress Core < 2.1.3 - Authorization Bypass
medium
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
- CVSS:
- 4.3
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Apr 3, 2007
CVE-2007-1893 on NVD →
WordPress Core 2.2.1 - Backdoor
critical
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru ca...
- CVSS:
- 9.8
- Affected:
- 2.2.1 – 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Mar 3, 2007
CVE-2007-1277 on NVD →
WordPress Core 2.1.1 - Supply Chain Compromise
critical
Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress sites.
- CVSS:
- 9.8
- Affected:
- 2.1.1 – 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 2, 2007
WordPress Core <= 2.1.1 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.
- CVSS:
- 6.4
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 2, 2007
CVE-2007-1230 on NVD →
WordPress Core <= 2.1.1 - Cross-Site Scripting
medium
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and ste...
- CVSS:
- 6.4
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 2, 2007
CVE-2007-1244 on NVD →
WordPress Core < 2.09 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vec...
- CVSS:
- 7.2
- Affected:
- up to 2.0.9, 2.1 – 2.1
- Fixed in:
- 2.0.9
- Disclosed:
- Feb 21, 2007
CVE-2007-1049 on NVD →
WordPress Core <= 3.0.4 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within...
- CVSS:
- 6.4
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Feb 11, 2007
CVE-2011-0700 on NVD →
WordPress Core < 2.1 - Directory Traversal
medium
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes...
- CVSS:
- 6.5
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jan 24, 2007
CVE-2007-0541 on NVD →
WordPress Core < 2.1 - Full Path Disclosure
medium
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.
- CVSS:
- 5.3
- Affected:
- up to 2.0.11
- Fixed in:
- 2.1
- Disclosed:
- Jan 22, 2007
CVE-2008-0195 on NVD →
WordPress Core < 2.1 - Denial of Service
medium
The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jan 22, 2007
CVE-2007-0539 on NVD →
WordPress Core < 2.0.7 - SQL Injection
high
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vu...
- CVSS:
- 8.8
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 15, 2007
CVE-2007-0233 on NVD →
WordPress Core < 2.0.7 - Full Path Disclosure
medium
WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.
- CVSS:
- 5.3
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 15, 2007
CVE-2007-0262 on NVD →
WordPress Core <= 2.0.5 - SQL Injection
critical
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.
- CVSS:
- 9.8
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 5, 2007
CVE-2007-0107 on NVD →
WordPress Core <= 2.0.5 - Cross-Site Request Forgery to Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new l...
- CVSS:
- 8.8
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 5, 2007
CVE-2007-0106 on NVD →
WordPress Core <= 2.0.5 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.
- CVSS:
- 6.4
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 5, 2007
CVE-2006-6808 on NVD →
WordPress < 2.0.6 - Username Enumeration via Error Messages
medium
wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
- CVSS:
- 5.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 5, 2007
CVE-2007-0109 on NVD →
WordPress Core 2.0.2 - 2.0.5 - Sensitive Information Disclosure
medium
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) heade...
- CVSS:
- 5.3
- Affected:
- 2.0.2 – 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 5, 2007
CVE-2006-4743 on NVD →
WordPress Core <= 2.0.4 - Directory Traversal
medium
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
- CVSS:
- 6.5
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 27, 2006
CVE-2006-5705 on NVD →
WordPress Core <= 2.0.4 - Denial of Service
medium
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic...
- CVSS:
- 6.5
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 27, 2006
CVE-2006-6017 on NVD →
WordPress Core < 2.0.5 - User Metadata Information Disclosure
medium
wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Sep 18, 2006
CVE-2006-6016 on NVD →
WordPress Core < 1.5.2 - Full Path Disclosure
medium
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error...
- CVSS:
- 5.3
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Aug 14, 2006
CVE-2005-4463 on NVD →
WordPress Core <= 2.0.3 - Denial of Service
medium
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2...
- CVSS:
- 6.5
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Jul 29, 2006
CVE-2008-0194 on NVD →
WordPress Core < 2.0.4 - Full Path Disclosure
medium
WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.
- CVSS:
- 5.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Jul 29, 2006
CVE-2006-3390 on NVD →
WordPress Core < 2.0.4 - Privilege Escalation
critical
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can registe...
- CVSS:
- 9.8
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Jul 9, 2006
CVE-2006-4028 on NVD →
WordPress Core < 2.0.3 - Remote Code Execution
high
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/user...
- CVSS:
- 8.8
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 1, 2006
CVE-2006-2667 on NVD →
WordPress Core < 2.0.3 - IP Address Spoofing
medium
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
- CVSS:
- 5.3
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 1, 2006
CVE-2006-2702 on NVD →
WordPress Core < 2.0.2 - Sensitive Information Disclosure
high
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9)...
- CVSS:
- 7.5
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 10, 2006
CVE-2006-0986 on NVD →
WordPress Core <= 2.0.1 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
- CVSS:
- 7.2
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 10, 2006
CVE-2006-0985 on NVD →
WordPress Core < 2.0.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 10, 2006
CVE-2007-5105 on NVD →
WordPress Core < 2.0.2 - Reflected Cross-Site Scripting
medium
Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
- CVSS:
- 6.1
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 10, 2006
CVE-2006-1263 on NVD →
WordPress Core < 2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).
- CVSS:
- 6.1
- Affected:
- up to 2.0
- Fixed in:
- 2.0.1
- Disclosed:
- Jan 31, 2006
CVE-2006-1796 on NVD →
WordPress Core <= 1.5.2 - SQL Injection
high
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.
- CVSS:
- 7.2
- Affected:
- up to 1.5.2
- Fixed in:
- 2.0
- Disclosed:
- Dec 31, 2005
CVE-2006-1012 on NVD →
WordPress Core < 1.5.2 - Remote Code Execution
high
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
- CVSS:
- 8.8
- Affected:
- up to 1.5.1.3
- Fixed in:
- 1.5.2
- Disclosed:
- Aug 9, 2005
CVE-2005-2612 on NVD →
WordPress Core < 1.5.1.3 - SQL Injection
high
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.
- CVSS:
- 8.8
- Affected:
- up to 1.5.1.3
- Fixed in:
- 1.5.1.3
- Disclosed:
- Jun 29, 2005
CVE-2005-2108 on NVD →
WordPress Core < 1.5.1.3 - Sensitive Information Disclosure
high
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect Wo...
- CVSS:
- 7.3
- Affected:
- up to 1.5.1.2
- Fixed in:
- 1.5.1.3
- Disclosed:
- Jun 29, 2005
CVE-2005-2110 on NVD →
WordPress Core <= 1.5.1.2 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.5.1.2
- Fixed in:
- 1.5.1.3
- Disclosed:
- Jun 29, 2005
CVE-2005-2107 on NVD →
WordPress Core < 1.5.1.3 - Arbitrary Email Content Change
medium
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
- CVSS:
- 5.3
- Affected:
- up to 1.5.1.2
- Fixed in:
- 1.5.1.3
- Disclosed:
- Jun 29, 2005
CVE-2005-2109 on NVD →
WordPress Core <= 1.5 - Stored Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.
- CVSS:
- 6.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1.2
- Disclosed:
- Jun 27, 2005
CVE-2005-1102 on NVD →
WordPress Core < 1.5.1.2 - SQL Injection
high
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.
- CVSS:
- 8.8
- Affected:
- up to 1.5.1.1
- Fixed in:
- 1.5.1.2
- Disclosed:
- May 27, 2005
CVE-2005-1810 on NVD →
WordPress Core < 1.5.1 - SQL Injection
high
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- May 9, 2005
CVE-2005-1687 on NVD →
WordPress Core < 1.5.1 - Full Path Disclosure
medium
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
- CVSS:
- 5.3
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- May 9, 2005
CVE-2005-1688 on NVD →
WordPress Core < 1.2.1 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameter...
- CVSS:
- 6.1
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Oct 6, 2004
CVE-2004-1559 on NVD →
WordPress Core <= 1.2 - HTTP Response Splitting
medium
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
- CVSS:
- 5.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Oct 6, 2004
CVE-2004-1584 on NVD →
WordPress Core < 0.72 - SQL Injection
high
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
- CVSS:
- 8.8
- Affected:
- up to 0.72
- Fixed in:
- 0.72
- Disclosed:
- Oct 11, 2003
CVE-2003-1598 on NVD →
WordPress Core <= 0.70 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
- CVSS:
- 9.8
- Affected:
- up to 0.70
- Fixed in:
- 0.71
- Disclosed:
- Jun 9, 2003
CVE-2003-1599 on NVD →
No data available
unknown
- Fix:
- No patched version reported
No data available
unknown
- Fix:
- No patched version reported