WordPress core

WordPress Core Vulnerabilities

391 known security issues reported for the WordPress Core WordPress WordPress core. Most recent disclosed Aug 12, 2026.

17 critical 97 high 266 medium 9 low

Running WordPress Core on your site? Check whether your installed version is affected.

Scan your site free

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

high

WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0.3. This is due to insufficient validation in the `WP_Image_Editor_Imagick::load()` image-processing path before passing uploaded files or streams to Imagick, which can interpret attacker-supplied ima...

CVSS:
8.8
Affected:
4.7.0 – 4.7.34, 4.8.0 – 4.8.29, 4.9.0 – 4.9.30, 5.0.0 – 5.0.26, 5.1.0 – 5.1.23, 5.2.0 – 5.2.25, 5.3.0 – 5.3.22, 5.4.0 – 5.4.20, 5.5.0 – 5.5.19, 5.6.0 – 5.6.18, 5.7.0 – 5.7.16, 5.8.0 – 5.8.14, 5.9.0 – 5.9.15, 6.0.0 – 6.0.13, 6.1.0 – 6.1.11, 6.2.0 – 6.2.10, 6.3.0 – 6.3.9, 6.4.0 – 6.4.9, 6.5.0 – 6.5.9, 6.6.0 – 6.6.6, 6.7.0 – 6.7.6, 6.8.0 – 6.8.7, 6.9.0 – 6.9.6, 7.0.0 – 7.0.3
Fixed in:
4.7.35
Disclosed:
Aug 12, 2026

CVE-2026-65640 on NVD →

WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Emoji Settings Element

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the emoji settings element in all versions up to, and including, 7.0.2 due to insufficient restrictions on submitted post content. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter

medium

WordPress Core is vulnerable to Reflected Cross-Site Scripting via the 'log' parameter in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping of the authentication error messages rendered on the login screen. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

CVE-2026-64638 on NVD →

WordPress Core <= 7.0.2 - Unauthenticated Blind Server-Side Request Forgery

medium

WordPress Core is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 7.0.2 due to insufficient validation of the destination address, as not all reserved and internal IP address ranges are blocked. This makes it possible for unauthenticated attackers to make web requests to arbitrary...

CVSS:
5.8
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Authenticated (Author+) CSS Injection

medium

WordPress Core is vulnerable to CSS Injection in all versions up to, and including, 7.0.2 due to insufficient sanitization of user supplied CSS. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary CSS into posts, altering the appearance and content of pages render...

CVSS:
5.5
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Unauthenticated Sensitive Information Exposure via Comment Feeds

medium

WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.2 via the comment feeds due to insufficient restrictions on internal notes, which are not excluded from feed output. This makes it possible for unauthenticated attackers to extract the contents of internal notes tha...

CVSS:
5.3
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Quick Edit

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via Quick Edit in all versions up to, and including, 7.0.2 due to insufficient escaping of user display names. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execu...

CVSS:
4.9
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Email Change Confirmation Bypass

medium

WordPress Core is vulnerable to an Email Change Confirmation Bypass in all versions up to, and including, 7.0.2 due to inconsistent validation of the new email address when a user profile is updated. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email address...

CVSS:
4.3
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Site Creation on Multisite

medium

WordPress Core is vulnerable to unauthorized site creation due to a missing check on the active signup policy in the 'gimmeanotherblog' signup action in all versions up to, and including, 7.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new sites on a multisit...

CVSS:
4.3
Affected:
4.7.0 – 4.7.33, 4.8.0 – 4.8.28, 4.9.0 – 4.9.29, 5.0.0 – 5.0.25, 5.1.0 – 5.1.22, 5.2.0 – 5.2.24, 5.3.0 – 5.3.21, 5.4.0 – 5.4.19, 5.5.0 – 5.5.18, 5.6.0 – 5.6.17, 5.7.0 – 5.7.15, 5.8.0 – 5.8.13, 5.9.0 – 5.9.13, 6.0.0 – 6.0.12, 6.1.0 – 6.1.10, 6.2.0 – 6.2.9, 6.3.0 – 6.3.8, 6.4.0 – 6.4.8, 6.5.0 – 6.5.8, 6.6.0 – 6.6.5, 6.7.0 – 6.7.5, 6.8.0 – 6.8.6, 6.9.0 – 6.9.5, 7.0.0 – 7.0.2
Fixed in:
4.7.34
Disclosed:
Aug 8, 2026

WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion

critical

WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoint (/wp-json/batch/v1). This is due to a route/validation desynchronization that allows a validated sub-request to be dispatched to an unintended callback, bypassing the allow_batch restriction, with...

CVSS:
9.8
Affected:
6.9 – 6.9.5, 7.0 – 7.0.2
Fixed in:
6.9.5
Disclosed:
Jul 17, 2026

CVE-2026-63030 on NVD →

WordPress Core 6.8 - 7.0.1 - Unauthenticated SQL Injection via author__not_in Parameter

high

WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 - 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
7.5
Affected:
6.8 – 6.8.5, 6.9 – 6.9.5, 7.0 – 7.0.2
Fixed in:
6.8.6
Disclosed:
Jul 17, 2026

CVE-2026-60137 on NVD →

WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload

medium

WordPress core is vulnerable to XML External Entity (XXE) Injection via the bundled getID3 library in all versions up to and including 6.9.1. This is due to the `GETID3_LIBXML_OPTIONS` constant including the `LIBXML_NOENT` flag, which enables XML entity substitution during parsing. When WordPress processes media files...

CVSS:
6.5
Affected:
6.8 – 6.8.3, 6.9 – 6.9.1
Fixed in:
6.8.4
Disclosed:
Mar 10, 2026

WordPress <= 6.9.1 - Unauthenticated Blind Server-Side Request Forgery via XML-RPC Pingback Discovery

medium

WordPress core is vulnerable to Blind Server-Side Request Forgery in all versions up to and including 6.9.1. This is due to the `WP_HTTP_IXR_Client` class using `wp_remote_post()` instead of the safer `wp_safe_remote_post()` when making outgoing XML-RPC pingback requests. This makes it possible for unauthenticated atta...

CVSS:
5.8
Affected:
6.8 – 6.8.3, 6.9 – 6.9.1
Fixed in:
6.8.4
Disclosed:
Mar 10, 2026

WordPress <= 6.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Navigation Menu Items

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via admin settings in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute wh...

CVSS:
4.4
Affected:
6.8 – 6.8.3, 6.9 – 6.9.1
Fixed in:
6.8.4
Disclosed:
Mar 10, 2026

WordPress <= 6.9.1 - Cross-Site Scripting via Client-Side Template Override in Admin Area

medium

WordPress core is vulnerable to Cross-Site Scripting via client-side template overriding in the admin area in all versions up to and including 6.9.1. The `wp.template()` JavaScript function uses `document.getElementById()` to locate templates, which matches any HTML element by ID regardless of element type. WordPress a...

CVSS:
4.4
Affected:
6.8 – 6.8.3, 6.9 – 6.9.1
Fixed in:
6.8.4
Disclosed:
Mar 10, 2026

WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API

medium

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments c...

CVSS:
4.3
Affected:
6.9 – 6.9.1
Fixed in:
6.9.2
Disclosed:
Mar 10, 2026

CVE-2026-3906 on NVD →

WordPress <= 6.9.1 - Missing Authorization to Authenticated (Author+) Sensitive Information Disclosure via query-attachments AJAX Endpoint

medium

WordPress core is vulnerable to Missing Authorization in all versions up to and including 6.9.1. This is due to a missing capability check on the `uploadedToTitle` and `uploadedToLink` fields in the `wp_prepare_attachment_for_js()` function. When querying media attachments via the AJAX `query-attachments` endpoint, the...

CVSS:
4.3
Affected:
6.8 – 6.8.3, 6.9 – 6.9.1
Fixed in:
6.8.4
Disclosed:
Mar 10, 2026

WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever...

CVSS:
6.4
Affected:
up to 4.7, 4.7 – 4.7.30, 4.8 – 4.8.26, 4.9 – 4.9.27, 5.0 – 5.0.23, 5.1 – 5.1.20, 5.2 – 5.2.22, 5.3 – 5.3.19, 5.4 – 5.4.17, 5.5 – 5.5.16, 5.6 – 5.6.15, 5.7 – 5.7.13, 5.8 – 5.8.11, 5.9 – 5.9.11, 6.0 – 6.0.10, 6.1 – 6.1.8, 6.2 – 6.2.7, 6.3 – 6.3.6, 6.4 – 6.4.6, 6.5 – 6.5.6, 6.6 – 6.6.3, 6.7 – 6.7.3, 6.8 – 6.8.2
Fixed in:
4.7.31
Disclosed:
Sep 22, 2025

CVE-2025-58674 on NVD →

WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure

medium

WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts they should not have access to.

CVSS:
4.3
Affected:
4.7 – 4.7.30, 4.8 – 4.8.26, 4.9 – 4.9.27, 5.0 – 5.0.23, 5.1 – 5.1.20, 5.2 – 5.2.22, 5.3 – 5.3.19, 5.4 – 5.4.17, 5.5 – 5.5.16, 5.6 – 5.6.15, 5.7 – 5.7.13, 5.8 – 5.8.11, 5.9 – 5.9.11, 6.0 – 6.0.10, 6.1 – 6.1.8, 6.2 – 6.2.7, 6.3 – 6.3.6, 6.4 – 6.4.6, 6.5 – 6.5.6, 6.6 – 6.6.3, 6.7 – 6.7.3, 6.8 – 6.8.2
Fixed in:
4.7.31
Disclosed:
Sep 22, 2025

CVE-2025-58246 on NVD →

WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
Fixed in:
5.9.10
Disclosed:
Jun 24, 2024

CVE-2024-31111 on NVD →

WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
Fixed in:
5.9.10
Disclosed:
Jun 24, 2024

CVE-2024-6307 on NVD →

WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal

medium

WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This makes it possible for authenticated attackers, with Contributor-level access and above, to include arbitrary HTML Files on sites running Windows.

CVSS:
4.3
Affected:
up to 4.1, 4.1 – 4.1.40, 4.2 – 4.2.37, 4.3 – 4.3.33, 4.4 – 4.4.32, 4.5 – 4.5.31, 4.6 – 4.6.28, 4.7 – 4.7.28, 4.8 – 4.8.24, 4.9 – 4.9.25, 5.0 – 5.0.21, 5.1 – 5.1.18, 5.2 – 5.2.20, 5.3 – 5.3.17, 5.4 – 5.4.15, 5.5 – 5.5.14, 5.6 – 5.6.13, 5.7 – 5.7.11, 5.8 – 5.8.9, 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, 6.2 – 6.2.5, 6.3 – 6.3.4, 6.4 – 6.4.4, 6.5 – 6.5.4
Fixed in:
4.1.41
Disclosed:
Jun 24, 2024

CVE-2024-32111 on NVD →

WordPress Core < 6.5.2 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block

high

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
7.2
Affected:
6.0 – 6.0.7, 6.1 – 6.1.5, 6.2 – 6.2.4, 6.3 – 6.3.3, 6.4 – 6.4.3, 6.5 – 6.5.1
Fixed in:
6.0.8
Disclosed:
Apr 9, 2024

CVE-2024-4439 on NVD →

WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink

medium

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.

CVSS:
5.3
Affected:
up to 6.4.3
Fixed in:
6.5
Disclosed:
Apr 4, 2024

CVE-2023-5692 on NVD →

WordPress Core 6.4.0 - 6.4.1 - Remote Code Execution POP Chain

critical

WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there being a magic method __destruct in the WP_HTML_Token class. This makes it possible for attackers to achieve remote code execution when another deserialization/PHP Object Injection vulnerability is pre...

CVSS:
9.8
Affected:
6.4.0 – 6.4.0, 6.4.1 – 6.4.1
Fixed in:
6.4.2
Disclosed:
Dec 6, 2023

CVE-2024-31211 on NVD →

WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges and above to inject arbitrary web scrip...

CVSS:
6.4
Affected:
5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
5.9.8
Disclosed:
Oct 12, 2023

CVE-2023-38000 on NVD →

WordPress Core 6.3 - 6.3.1 - Authenticated(Contributor+) Cross-Site Scripting via Footnotes Block

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the footnotes block in versions between 6.3 and 6.3.1 due to insufficient input sanitization and output escaping on the footnotes block. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web...

CVSS:
6.4
Affected:
6.3 – 6.3.1
Fixed in:
6.3.2
Disclosed:
Oct 12, 2023

WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests

medium

WordPress Core is vulnerable to Reflected Cross-Site Scripting via the ‘success_url’ and 'reject_url' parameters when requesting application passwords in versions between 5.6 and 6.3.1 due to insufficient input sanitization and output escaping of pseudo protocol URIs. This makes it possible for unauthenticated attacker...

CVSS:
6.1
Affected:
5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
5.6.12
Disclosed:
Oct 12, 2023

WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode

medium

WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of input validation on the 'shortcode' parameter in the parse_media_shortcode AJAX function. This allows authenticated attackers, with subscriber-level privileges and above, to execute arbitrary shortcode...

CVSS:
5.4
Affected:
up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
4.1.39
Disclosed:
Oct 12, 2023

WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint

medium

WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column. This can allow unauthent...

CVSS:
5.3
Affected:
4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
4.7.27
Disclosed:
Oct 12, 2023

CVE-2023-5561 on NVD →

WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning

medium

WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases where the X-HTTP-Method-Override header was sent in a request to a REST endpoint and the endpoint returned a 4xx error, the error could be cached, resulting in denial of service.

CVSS:
5.3
Affected:
4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
4.7.27
Disclosed:
Oct 12, 2023

WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts

medium

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments listing. This allows authenticated users, with contributor-level privileges or above, to view comments on protected posts.

CVSS:
4.3
Affected:
up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
4.1.39
Disclosed:
Oct 12, 2023

CVE-2023-39999 on NVD →

WordPress Core < 6.2.2 - Shortcode Execution in User Generated Content

medium

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require Subscriber or Contributor-leve...

CVSS:
6.5
Affected:
5.9 – 5.9.7, 6.0 – 6.0.5, 6.1 – 6.1.3, 6.2 – 6.2.2
Fixed in:
5.9.7
Disclosed:
May 19, 2023

WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content

medium

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require Subscriber or Contributor-level...

CVSS:
6.5
Affected:
5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
Fixed in:
5.9.6
Disclosed:
May 19, 2023

WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes

medium

WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it possible for authenticated attackers with contributor-level and above permissions to embed arbitrary content in HTML comments on the page, though Cross-Site Scripting may be possible when combined with a...

CVSS:
6.4
Affected:
up to 4.1, 4.1 – 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
Fixed in:
4.1.38
Disclosed:
May 16, 2023

WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery

medium

WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient validation of the protocol in the response when processing oEmbed discovery. This makes it possible for authenticated attackers with contributor-level and above permissions to use a crafted oEmbed payl...

CVSS:
6.4
Affected:
up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
Fixed in:
4.1.38
Disclosed:
May 16, 2023

WordPress Core < 6.2.1 - Directory Traversal

medium

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form,...

CVSS:
5.4
Affected:
up to 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
Fixed in:
4.1.38
Disclosed:
May 16, 2023

CVE-2023-2745 on NVD →

WordPress Core < 6.2.1 - Cross-Site Request Forgery

medium

WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the ‘wp_ajax_set_attachment_thumbnail’ AJAX function in versions up to, and including, 6.2. This allows unauthenticated users to update the thumbnail image associated with existing attachments, granted they can trick an authen...

CVSS:
4.3
Affected:
up to 4.1, 4.1 – 4.1.38, 4.2 – 4.2.35, 4.3 – 4.3.31, 4.4 – 4.4.30, 4.5 – 4.5.29, 4.6 – 4.6.26, 4.7 – 4.7.26, 4.8 – 4.8.22, 4.9 – 4.9.23, 5.0 – 5.0.19, 5.1 – 5.1.16, 5.2 – 5.2.18, 5.3 – 5.3.15, 5.4 – 5.4.13, 5.5 – 5.5.12, 5.6 – 5.6.11, 5.7 – 5.7.9, 5.8 – 5.8.7, 5.9 – 5.9.6, 6.0 – 6.0.4, 6.1 – 6.1.2, 6.2 – 6.2.1
Fixed in:
4.1.38
Disclosed:
May 16, 2023

WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query

critical

WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where “AND” and “OR” present in the query. This may make it possible for attackers to achieve SQL Injection when another plugin or theme is installed on the site that allows WP_Date_Query to be used insecurely...

CVSS:
9.8
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection

high

WordPress Core is vulnerable to SQL Injection in the Media Library that can be leveraged to exploit a Reflected Cross-Site Scripting issue in versions up to 6.0.3. This is due to insufficient escaping on user supplied values passed to a SQL query. This makes it possible for an attacker to achieved JavaScript code exec...

CVSS:
8.8
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

CVE-2022-43497 on NVD →

WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php

high

WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to the fact that the any request to wp-trackback.php would assume the identity of the user whose cookies are sent with the request. This would make it possible for an unauthenticated user to trigger a tr...

CVSS:
8.8
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Stored Cross-Site Scripting via wp-mail.php

high

WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validation on what level the user was sending the email post and therefore did not perform any sanitization on the submitted post data. This meant that users without the unfiltered_html capability, with acce...

CVSS:
7.2
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

CVE-2022-43504 on NVD →

WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks

medium

WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...

CVSS:
6.4
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

CVE-2022-43500 on NVD →

WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to insufficient escaping on the 'Blog Name' value that could be edited and become executable with the right payload while in the theme customizer. This would make it possible for authenticated attacker wi...

CVSS:
5.5
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3. This is due to insufficient escaping and sanitization on the values being stored during a comment update. This makes it possible for authenticated users with high level permissions, such as an edito...

CVSS:
5.5
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Open Redirect

medium

WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Referer' header and _wp_http_referer request parameter when a user accesses a link with an expired or invalid nonce. This would make it possible for an attacker to redirect a victim to a potentially mal...

CVSS:
5.4
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Information Disclosure (Email Address)

medium

WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality is enabled, it may log post author's email addresses in a way that may be publicly accessible. This could make it possible for attackers to steal post author's email addresses and use that for further...

CVSS:
5.3
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

CVE-2022-43504 on NVD →

WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API

medium

WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a c...

CVSS:
4.3
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Shared User Instance Weakness

low

WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS and CSRF in wp-mail.php and wp-trackback.php vulnerabilities. The previous functionality may ha...

CVSS:
3.7
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)

low

WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a con...

CVSS:
3.7
Affected:
up to 3.6.1, 3.7 – 3.7.39, 3.8 – 3.8.39, 3.9 – 3.9.37, 4.0 – 4.0.36, 4.1 – 4.1.36, 4.2 – 4.2.33, 4.3 – 4.3.29, 4.4 – 4.4.28, 4.5 – 4.5.27, 4.6 – 4.6.24, 4.7 – 4.7.24, 4.8 – 4.8.20, 4.9 – 4.9.21, 5.0 – 5.0.17, 5.1 – 5.1.14, 5.2 – 5.2.16, 5.3 – 5.3.13, 5.4 – 5.4.11, 5.5 – 5.5.10, 5.6 – 5.6.9, 5.7 – 5.7.7, 5.8 – 5.8.5, 5.9 – 5.9.4, 6.0 – 6.0.2
Fixed in:
3.7.40
Disclosed:
Oct 18, 2022

WordPress Core - All known versions - Unauthenticated Blind Server Side Request Forgery

medium

WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This is due to a Time-of-Check-Time-of-Use (TOC-TOU) race condition between validation checks and HTTP requests that makes it possible for URLs to be validated and then changed before being used by the soft...

CVSS:
4
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Sep 6, 2022

CVE-2022-3590 on NVD →

WordPress Core < 6.0.2 - Authenticated SQL Injection

high

WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via the LIMIT parameter passed through the get_bookmarks function. This can be exploited on default WordPress installations by users with high-level privileges, such as an editor or administrator, and it...

CVSS:
8
Affected:
up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
Fixed in:
3.7.39
Disclosed:
Aug 30, 2022

WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function

medium

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that ex...

CVSS:
4.9
Affected:
up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
Fixed in:
3.7.39
Disclosed:
Aug 30, 2022

CVE-2022-4973 on NVD →

WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors

medium

WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicious content is injected into plugin code that triggers when an error occurs during plugin de-activation or during deletion. This requires an attacker have access to the modify the error message that is...

CVSS:
4.4
Affected:
up to 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, 3.9 – 3.9.36, 4.0 – 4.0.35, 4.1 – 4.1.35, 4.2 – 4.2.32, 4.3 – 4.3.28, 4.4 – 4.4.27, 4.5 – 4.5.26, 4.6 – 4.6.23, 4.7 – 4.7.23, 4.8 – 4.8.19, 4.9 – 4.9.20, 5.0 – 5.0.16, 5.1 – 5.1.13, 5.2 – 5.2.15, 5.3 – 5.3.12, 5.4 – 5.4.10, 5.5 – 5.5.9, 5.6 – 5.6.8, 5.7 – 5.7.6, 5.8 – 5.8.4, 5.9 – 5.9.3, 6.0 – 6.0.1
Fixed in:
3.7.39
Disclosed:
Aug 30, 2022

WordPress Core < 5.9.1 - jQuery Prototype Pollution

high

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3, 5.9 – 5.9.1
Fixed in:
3.7.38
Disclosed:
Mar 11, 2022

CVE-2021-20083 on NVD →

WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

WordPress Core in versions 5.9 - 5.9.1 is vulnerable to Contributor+ stored Cross-Site Scripting via the double JSON encoded payloads set in the 'isGlobalStylesUserThemeJSON' parameter which is updatable via the post editor.

CVSS:
6.4
Affected:
5.9 – 5.9.2
Fixed in:
5.9.2
Disclosed:
Mar 11, 2022

WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor

medium

WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3, 5.9 – 5.9.1
Fixed in:
3.7.38
Disclosed:
Mar 11, 2022

WordPress Core < 5.8.3 - Authenticated (Author+) Stored Cross Site Scripting

high

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version...

CVSS:
8
Affected:
3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
Fixed in:
3.7.37
Disclosed:
Jan 6, 2022

CVE-2022-21662 on NVD →

WordPress Core < 5.8.3 - SQL Injection via WP_Meta_Query

high

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed...

CVSS:
7.4
Affected:
4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
Fixed in:
4.1.34
Disclosed:
Jan 6, 2022

CVE-2022-21664 on NVD →

WordPress Core < 5.8.3 - Super Admin Multi-Site Installation Object Injection

medium

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versio...

CVSS:
6.6
Affected:
3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
Fixed in:
3.7.37
Disclosed:
Jan 6, 2022

CVE-2022-21663 on NVD →

WordPress Core < 5.8 - Dependency Confusion

high

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet...

CVSS:
8.1
Affected:
up to 5.7.5
Fixed in:
5.8
Disclosed:
Nov 25, 2021

CVE-2021-44223 on NVD →

WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3

medium

WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.

CVSS:
5.3
Affected:
up to 5.2, 5.2 – 5.2.12, 5.3 – 5.3.9, 5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
Fixed in:
5.2.13
Disclosed:
Nov 10, 2021

WordPress Core 5.4 - 5.8 - Authenticated Stored Cross-Site Scripting

high

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permi...

CVSS:
7.6
Affected:
5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
Fixed in:
5.4.7
Disclosed:
Sep 9, 2021

CVE-2021-39201 on NVD →

WordPress Core 5.8 beta - Stored Cross-Site Scripting in Custom HTML Block

high

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This ha...

CVSS:
7.6
Affected:
5.8 beta 1 – 5.8 beta 2
Fixed in:
5.8
Disclosed:
Sep 9, 2021

CVE-2021-39202 on NVD →

WordPress Core 5.8 beta - Block Editor Authorization Bypass

medium

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 b...

CVSS:
6.8
Affected:
5.8 beta 1 – 5.8 beta 1
Fixed in:
5.8
Disclosed:
Sep 9, 2021

CVE-2021-39203 on NVD →

WordPress Core < 5.8.1 - LoDash Update

medium

WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the LoDash component which is identified as CVE-2020-8203.

CVSS:
6.1
Affected:
5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
Fixed in:
5.4.7
Disclosed:
Sep 9, 2021

CVE-2020-8203 on NVD →

WordPress Core 5.4 - 5.8 - Sensitive Information Disclosure

medium

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has...

CVSS:
5.3
Affected:
5.4 – 5.4.7, 5.5 – 5.5.6, 5.6 – 5.6.5, 5.7 – 5.7.3, 5.8 – 5.8.1
Fixed in:
5.4.7
Disclosed:
Sep 9, 2021

CVE-2021-39200 on NVD →

WordPress Core < 5.7.1 - XXE Injection

high

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPr...

CVSS:
7.1
Affected:
4.7 – 4.7.20, 4.8 – 4.8.16, 4.9 – 4.9.17, 5.0 – 5.0.12, 5.1 – 5.1.9, 5.2 – 5.2.10, 5.3 – 5.3.7, 5.4 – 5.4.5, 5.5 – 5.5.4, 5.6 – 5.6.3, 5.7 – 5.7.1
Fixed in:
4.7.20
Disclosed:
Apr 15, 2021

CVE-2021-29447 on NVD →

WordPress Core < 5.7.1 - Sensitive Information Disclosure

medium

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommen...

CVSS:
6.5
Affected:
4.7 – 4.7.20, 4.8 – 4.8.16, 4.9 – 4.9.17, 5.0 – 5.0.12, 5.1 – 5.1.9, 5.2 – 5.2.10, 5.3 – 5.3.7, 5.4 – 5.4.5, 5.5 – 5.5.4, 5.6 – 5.6.3, 5.7 – 5.7.1
Fixed in:
4.7.20
Disclosed:
Apr 15, 2021

CVE-2021-29450 on NVD →

WordPress Core < 5.8.3 - SQL Injection via WP_Query

high

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older af...

CVSS:
8
Affected:
3.7 – 3.7.37, 3.8 – 3.8.37, 3.9 – 3.9.35, 4.0 – 4.0.34, 4.1 – 4.1.34, 4.2 – 4.2.31, 4.3 – 4.3.27, 4.4 – 4.4.26, 4.5 – 4.5.25, 4.6 – 4.6.22, 4.7 – 4.7.22, 4.8 – 4.8.18, 4.9 – 4.9.19, 5.0 – 5.0.15, 5.1 – 5.1.12, 5.2 – 5.2.14, 5.3 – 5.3.11, 5.4 – 5.4.9, 5.5 – 5.5.8, 5.6 – 5.6.7, 5.7 – 5.7.5, 5.8 – 5.8.3
Fixed in:
3.7.37
Disclosed:
Jan 6, 2021

CVE-2022-21661 on NVD →

WordPress Core < 5.5.3 - PHP Object Injection Gadget

critical

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

CVSS:
9.8
Affected:
up to 3.7, 3.7 – 3.7.35, 3.8 – 3.8.35, 3.9 – 3.9.33, 4.0 – 4.0.32, 4.1 – 4.1.32, 4.2 – 4.2.29, 4.3 – 4.3.25, 4.4 – 4.4.24, 4.5 – 4.5.23, 4.6 – 4.6.20, 4.7 – 4.7.19, 4.8 – 4.8.15, 4.9 – 4.9.16, 5.0 – 5.0.11, 5.1 – 5.1.8, 5.2 – 5.2.9, 5.3 – 5.3.6, 5.4 – 5.4.4, 5.5 – 5.5.3
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2021-29476 on NVD →

WordPress Core < 5.5.2 - Privilege Escalation via XML-RPC

high

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28036 on NVD →

WordPress Core < 5.5.2 - Deserialization Gadget

high

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28032 on NVD →

WordPress Core < 5.5.2 - Privilege Escalation via XML-RPC

high

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28035 on NVD →

WordPress Core < 5.5.2 - Stored Cross-Site Scripting via post slugs

medium

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28038 on NVD →

WordPress Core < 5.5.2 - Reflected Cross-Site Scripting via Global Variables

medium

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28034 on NVD →

WordPress Core < 5.5.2 - Arbitrary File Deletion

medium

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28039 on NVD →

WordPress Core < 5.5.2 - Misconfiguration That Allows Trigger of New Installation

medium

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS:
4.8
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28037 on NVD →

WordPress Core < 5.5.2 - Cross-Site Request Forgery to Theme Image Change

medium

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28040 on NVD →

WordPress Core < 5.5.2 - Spam Embed on Multisite Installations

medium

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.34, 3.8 – 3.8.34, 3.9 – 3.9.32, 4.0 – 4.0.31, 4.1 – 4.1.31, 4.2 – 4.2.28, 4.3 – 4.3.24, 4.4 – 4.4.23, 4.5 – 4.5.22, 4.6 – 4.6.19, 4.7 – 4.7.18, 4.8 – 4.8.14, 4.9 – 4.9.15, 5.0 – 5.0.10, 5.1 – 5.1.6, 5.2 – 5.2.7, 5.3 – 5.3.4, 5.4 – 5.4.2, 5.5 – 5.5.1
Fixed in:
3.7.35
Disclosed:
Oct 29, 2020

CVE-2020-28033 on NVD →

WordPress Core < 5.4.2 - Authenticated Stored Cross-Site Scripting

medium

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in versi...

CVSS:
6.8
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-4047 on NVD →

WordPress Core < 5.4.2 - Open Redirect

medium

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6,...

CVSS:
5.7
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-4048 on NVD →

WordPress Core < 5.4.2 - Authenticated Stored Cross-Site Scripting

medium

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin. This has been patch...

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-4046 on NVD →

WordPress Core < 5.4.2 - Comment Disclosure

medium

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-25286 on NVD →

WordPress Core < 5.4.2 - Arbitrary User Meta Update

low

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along...

CVSS:
3.5
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-4050 on NVD →

WordPress Core < 5.4.2 - Self-Cross Site Scripting via Theme Folder Name

low

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the...

CVSS:
2.4
Affected:
up to 3.7, 3.7 – 3.7.33, 3.8 – 3.8.33, 3.9 – 3.9.31, 4.0 – 4.0.30, 4.1 – 4.1.30, 4.2 – 4.2.27, 4.3 – 4.3.23, 4.4 – 4.4.22, 4.5 – 4.5.21, 4.6 – 4.6.18, 4.7 – 4.7.17, 4.8 – 4.8.13, 4.9 – 4.9.14, 5.0 – 5.0.9, 5.1 – 5.1.5, 5.2 – 5.2.6, 5.3 – 5.3.3
Fixed in:
3.7.34
Disclosed:
Jun 10, 2020

CVE-2020-4049 on NVD →

WordPress Core < 5.4.1 - Authenticated (Author+) Cross-Site Scripting via File Uploads

medium

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via...

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11026 on NVD →

WordPress Core < 5.4.1 - Cross-Site Scripting in the Block Editor

medium

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a mi...

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11030 on NVD →

WordPress Core < 5.4.1 - Password Reset Link Non-Expiration

medium

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a...

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11027 on NVD →

WordPress Core < 5.4.1 - Reflected Cross Site Scripting

medium

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4...

CVSS:
5.8
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11029 on NVD →

WordPress Core < 5.4.1 - Authenticated Cross-Site Scripting via Customizer

medium

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5....

CVSS:
5.8
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11025 on NVD →

WordPress Core < 5.4.1 - Private Post Disclosure

medium

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.1...

CVSS:
5.8
Affected:
up to 3.7, 3.7 – 3.7.32, 3.8 – 3.8.32, 3.9 – 3.9.30, 4.0 – 4.0.29, 4.1 – 4.1.29, 4.2 – 4.2.26, 4.3 – 4.3.22, 4.4 – 4.4.21, 4.5 – 4.5.20, 4.6 – 4.6.17, 4.7 – 4.7.16, 4.8 – 4.8.12, 4.9 – 4.9.13, 5.0 – 5.0.8, 5.1 – 5.1.4, 5.2 – 5.2.5, 5.3 – 5.3.2, 5.4 – 5.4
Fixed in:
3.7.33
Disclosed:
Apr 29, 2020

CVE-2020-11028 on NVD →

WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting

medium

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript&colon; substring.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
Fixed in:
3.7.32
Disclosed:
Dec 13, 2019

CVE-2019-20041 on NVD →

WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting

medium

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
Fixed in:
3.7.32
Disclosed:
Dec 13, 2019

CVE-2019-20042 on NVD →

WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting

medium

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.

CVSS:
5.8
Affected:
up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4
Fixed in:
3.7.32
Disclosed:
Dec 13, 2019

CVE-2019-16781 on NVD →

WordPress Core < 5.3.1 - Stored Cross-Site Scripting via Block Editor

medium

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in...

CVSS:
5.8
Affected:
up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
Fixed in:
3.7.32
Disclosed:
Dec 13, 2019

CVE-2019-16780 on NVD →

WordPress Core < 5.3.1 - Authorization Bypass

medium

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass...

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.31, 3.8 – 3.8.31, 3.9 – 3.9.29, 4.0 – 4.0.28, 4.1 – 4.1.28, 4.2 – 4.2.25, 4.3 – 4.3.21, 4.4 – 4.4.20, 4.5 – 4.5.19, 4.6 – 4.6.16, 4.7 – 4.7.15, 4.8 – 4.8.11, 4.9 – 4.9.12, 5.0 – 5.0.7, 5.1 – 5.1.3, 5.2 – 5.2.4, 5.3 – 5.3
Fixed in:
3.7.32
Disclosed:
Dec 1, 2019

CVE-2019-20043 on NVD →

WordPress Core < 5.2.4 - Cache Poisoning

high

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS:
7.3
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17673 on NVD →

WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting

medium

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17672 on NVD →

WordPress Core < 5.2.4 - Type Confusion

medium

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS:
5.5
Affected:
up to 3.6.1, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17675 on NVD →

WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting via Customizer

medium

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17674 on NVD →

WordPress Core < 5.2.4 - Server Side Request Forgery

medium

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17669 on NVD →

WordPress Core < 5.2.4 - Server Side Request Forgery #2

medium

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.13, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17670 on NVD →

WordPress Core < 5.2.4 - Authorization Bypass

medium

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.30, 3.8 – 3.8.30, 3.9 – 3.9.28, 4.0 – 4.0.27, 4.1 – 4.1.27, 4.2 – 4.2.24, 4.3 – 4.3.20, 4.4 – 4.4.19, 4.5 – 4.5.18, 4.6 – 4.6.15, 4.7 – 4.7.14, 4.8 – 4.8.10, 4.9 – 4.9.11, 5.0 – 5.0.6, 5.1 – 5.1.2, 5.2 – 5.2.3
Fixed in:
3.7.31
Disclosed:
Oct 14, 2019

CVE-2019-17671 on NVD →

WordPress Core < 5.2.3 - Stored Cross-Site Scripting via Comments

high

WordPress before 5.2.3 allows XSS in stored comments.

CVSS:
7.2
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16218 on NVD →

WordPress Core < 5.2.3 - Cross-Site Scripting via Media Uploads

medium

WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16217 on NVD →

WordPress Core < 5.2.3 - Stored Cross-Site Scripting via Comments via URLs

medium

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16222 on NVD →

WordPress Core < 5.2.3 - Reflected Cross-Site Scripting

medium

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16221 on NVD →

WordPress Core < 5.2.3 - Authenticated Cross-Site Scripting via Post Previews

medium

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16223 on NVD →

WordPress Core < 5.2.3 - Reflected Cross-Site Scripting via Shortcode Previews

medium

WordPress before 5.2.3 allows XSS in shortcode previews.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16219 on NVD →

WordPress Core < 5.2.3 - Open Redirect

medium

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect.

CVSS:
4.6
Affected:
up to 3.7, 3.7 – 3.7.29, 3.8 – 3.8.29, 3.9 – 3.9.27, 4.0 – 4.0.26, 4.1 – 4.1.26, 4.2 – 4.2.23, 4.3 – 4.3.19, 4.4 – 4.4.18, 4.5 – 4.5.17, 4.6 – 4.6.13, 4.7 – 4.7.13, 4.8 – 4.8.9, 4.9 – 4.9.10, 5.0 – 5.0.5, 5.1 – 5.1.1, 5.2 – 5.2.2
Fixed in:
3.7.30
Disclosed:
Sep 5, 2019

CVE-2019-16220 on NVD →

WordPress Core < 5.1.1 - Cross-Site Request Forgery to Cross-Site Scripting via Comments

critical

WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in admi...

CVSS:
9.6
Affected:
up to 3.7, 3.7 – 3.7.28, 3.8 – 3.8.28, 3.9 – 3.9.26, 4.0 – 4.0.25, 4.1 – 4.1.25, 4.2 – 4.2.22, 4.3 – 4.3.18, 4.4 – 4.4.17, 4.5 – 4.5.16, 4.6 – 4.6.13, 4.7 – 4.7.12, 4.8 – 4.8.8, 4.9 – 4.9.9, 5.0 – 5.0.3, 5.1 – 5.1
Fixed in:
3.7.29
Disclosed:
Apr 12, 2019

CVE-2019-9787 on NVD →

WordPress Core < 5.0.1 - Remote Code Execution

high

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code i...

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Feb 19, 2019

CVE-2019-8942 on NVD →

WordPress Core <= 5.0.3 - Path Traversal and Local File Inclusion

medium

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS:
6.5
Affected:
up to 5.0.2
Fixed in:
5.0.3
Disclosed:
Feb 19, 2019

CVE-2019-8943 on NVD →

WordPress Core < 5.0.1 - PHP Object Injection

high

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20148 on NVD →

WordPress Core < 5.0.1 - Arbitrary File Deletion

high

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

CVSS:
7.7
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20147 on NVD →

WordPress Core < 5.0.1 - Sensitive Information Disclosure

high

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS:
7.5
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20151 on NVD →

WordPress Core < 5.0.1 - Stored Cross-Site Scripting via File Uploads

medium

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20149 on NVD →

WordPress Core < 5.0.1 - Authenticated Stored Cross-Site Scripting via Comments

medium

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20153 on NVD →

WordPress Core < 5.0.1 Reflected Cross-Site Scripting

medium

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20150 on NVD →

WordPress Core < 5.0.1 - Authorization Bypass

medium

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Dec 12, 2018

CVE-2018-20152 on NVD →

WordPress Core < 5.0.1 - PHAR Unserialization

high

WordPress Core versions before 5.0.1 contain a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in o...

CVSS:
7.5
Affected:
up to 3.7, 3.7 – 3.7.27, 3.8 – 3.8.27, 3.9 – 3.9.25, 4.0 – 4.0.24, 4.1 – 4.1.24, 4.2 – 4.2.21, 4.3 – 4.3.17, 4.4 – 4.4.16, 4.5 – 4.5.15, 4.6 – 4.6.12, 4.7 – 4.7.11, 4.8 – 4.8.7, 4.9 – 4.9.8, 5.0 – 5.0
Fixed in:
3.7.28
Disclosed:
Sep 6, 2018

CVE-2018-1000773 on NVD →

WordPress Core < 4.9 - Insecure Deserialization

high

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at...

CVSS:
8.8
Affected:
up to 4.9
Fixed in:
4.9
Disclosed:
Aug 16, 2018

CVE-2017-1000600 on NVD →

WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload

medium

In all current versions of WordPress Core before 6.4.3, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an atta...

CVSS:
6.6
Affected:
up to 4.1, 4.1 – 4.1.39, 4.2 – 4.2.36, 4.3 – 4.3.32, 4.4 – 4.4.31, 4.5 – 4.5.30, 4.6 – 4.6.27, 4.7 – 4.7.27, 4.8 – 4.8.23, 4.9 – 4.9.24, 5.0 – 5.0.20, 5.1 – 5.1.17, 5.2 – 5.2.19, 5.3 – 5.3.16, 5.4 – 5.4.14, 5.5 – 5.5.13, 5.6 – 5.6.12, 5.7 – 5.7.10, 5.8 – 5.8.8, 5.9 – 5.9.8, 6.0 – 6.0.6, 6.1 – 6.1.4, 6.2 – 6.2.3, 6.3 – 6.3.2, 6.4 – 6.4.2
Fixed in:
4.1.40
Disclosed:
Aug 4, 2018

CVE-2018-14028 on NVD →

WordPress Core < 4.9.7 - Authenticated Arbitrary File Deletion

high

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachm...

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.26, 3.8 – 3.8.26, 3.9 – 3.9.24, 4.0 – 4.0.23, 4.1 – 4.1.23, 4.2 – 4.2.20, 4.3 – 4.3.16, 4.4 – 4.4.15, 4.5 – 4.5.14, 4.6 – 4.6.11, 4.7 – 4.7.10, 4.8 – 4.8.6, 4.9 – 4.9.6
Fixed in:
3.7.27
Disclosed:
Jul 5, 2018

CVE-2018-12895 on NVD →

WordPress Core < 4.9.5 - Authenticated Stored Cross-Site Scripting via Generator Tag

medium

Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
Fixed in:
3.7.26
Disclosed:
Apr 3, 2018

CVE-2018-10102 on NVD →

WordPress Core < 4.9.5 - Open Redirect

medium

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
Fixed in:
3.7.26
Disclosed:
Apr 3, 2018

CVE-2018-10100 on NVD →

WordPress Core < 4.9.5 - Security Misconfiguration with URL Hostnames

medium

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.25, 3.8 – 3.8.25, 3.9 – 3.9.23, 4.0 – 4.0.22, 4.1 – 4.1.22, 4.2 – 4.2.19, 4.3 – 4.3.15, 4.4 – 4.4.14, 4.5 – 4.5.13, 4.6 – 4.6.10, 4.7 – 4.7.9, 4.8 – 4.8.5, 4.9 – 4.9.4
Fixed in:
3.7.26
Disclosed:
Apr 3, 2018

CVE-2018-10101 on NVD →

WordPress Core < 5.0 - Denial of Service

high

In WordPress before 5.0, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. It looks like most of the slowness was due to forcing PHP to repea...

CVSS:
7.5
Affected:
up to 5.0
Fixed in:
5.0
Disclosed:
Feb 5, 2018

CVE-2018-6389 on NVD →

WordPress Core < 4.9.2 - Authenticated Cross-Site Scripting

medium

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS:
6.4
Affected:
up to 3.6.1, 3.7 – 3.7.24, 3.8 – 3.8.24, 3.9 – 3.9.22, 4.0 – 4.0.21, 4.1 – 4.1.21, 4.2 – 4.2.18, 4.3 – 4.3.14, 4.4 – 4.4.13, 4.5 – 4.5.12, 4.6 – 4.6.9, 4.7 – 4.7.8, 4.8 – 4.8.4, 4.9 – 4.9.1
Fixed in:
3.7.25
Disclosed:
Jan 16, 2018

CVE-2018-5776 on NVD →

WordPress Core < 4.9.1- Stored Cross-Site Scripting via Language

medium

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
Fixed in:
3.7.24
Disclosed:
Nov 29, 2017

CVE-2017-17093 on NVD →

WordPress Core < 4.9.1 - Authenticated Stored Cross-Site Scripting

medium

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
Fixed in:
3.7.24
Disclosed:
Nov 29, 2017

CVE-2017-17092 on NVD →

WordPress Core < 4.9.1 - Reflected Cross-Site Scripting

medium

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
Fixed in:
3.7.24
Disclosed:
Nov 29, 2017

CVE-2017-17094 on NVD →

WordPress Core < 4.9.1 - Authorization Bypass

medium

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.23, 3.8 – 3.8.23, 3.9 – 3.9.21, 4.0 – 4.0.20, 4.1 – 4.1.20, 4.2 – 4.2.17, 4.3 – 4.3.13, 4.4 – 4.4.12, 4.5 – 4.5.11, 4.6 – 4.6.8, 4.7 – 4.7.7, 4.8 – 4.8.3, 4.9 – 4.9
Fixed in:
3.7.24
Disclosed:
Nov 29, 2017

CVE-2017-17091 on NVD →

WordPress Core < 4.8.3 - SQL Injection due to Double Prepare approach

critical

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS:
9.8
Affected:
up to 3.7, 3.7 – 3.7.22, 3.8 – 3.8.22, 3.9 – 3.9.20, 4.0 – 4.0.19, 4.1 – 4.1.19, 4.2 – 4.2.16, 4.3 – 4.3.12, 4.4 – 4.4.11, 4.5 – 4.5.10, 4.6 – 4.6.7, 4.7 – 4.7.6, 4.8 – 4.8.2
Fixed in:
3.7.23
Disclosed:
Oct 31, 2017

CVE-2017-16510 on NVD →

WordPress Core - All Known Versions - Cleartext Storage of wp_signups.activation_key

medium

All known versions of WordPress Core store cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspeci...

CVSS:
5.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Oct 10, 2017

CVE-2017-14990 on NVD →

WordPress Core < 4.9.1 - Cross-domain Flash injection

medium

WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS:
4.7
Affected:
up to 3.7, 3.7 – 3.7.24, 3.8 – 3.8.24, 3.9 – 3.9.23, 4.0 – 4.0.21, 4.1 – 4.1.21, 4.2 – 4.2.18, 4.3 – 4.3.14, 4.4 – 4.4.13, 4.5 – 4.5.12, 4.6 – 4.6.9, 4.7 – 4.7.8, 4.8 – 4.8.4, 4.9 – 4.9.1
Fixed in:
3.7.25
Disclosed:
Oct 10, 2017

CVE-2016-9263 on NVD →

WordPress Core < 4.8.2 - SQL Injection via Mishandled Placeholders

critical

Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

CVSS:
9.8
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14723 on NVD →

WordPress Core < 4.8.2 - Cross-Site Scripting via Shortcodes

medium

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14726 on NVD →

WordPress Core < 4.8.2 - Cross-Site Scripting via Template Name

medium

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14720 on NVD →

WordPress Core < 4.8.2 - Cross-Site Scripting in oEmbed

medium

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14724 on NVD →

WordPress Core < 4.8.2 - Cross-Site Scripting via Javascript: and Data: URLs

medium

Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14718 on NVD →

WordPress Core < 4.8.2 - Stored Cross-Site Scripting via Plugin Names

medium

Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14721 on NVD →

WordPress Core < 4.8.2 - Directory Traversal via Customizer

medium

Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

CVSS:
4.9
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14722 on NVD →

WordPress Core < 4.8.2 - Directory Traversal during unzip

medium

Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14719 on NVD →

WordPress Core < 4.8.2 - Open Redirect in Admin Dashboard

low

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS:
3.5
Affected:
up to 3.7, 3.7 – 3.7.21, 3.8 – 3.8.21, 3.9 – 3.9.19, 4.0 – 4.0.18, 4.1 – 4.1.18, 4.2 – 4.2.15, 4.3 – 4.3.11, 4.4 – 4.4.10, 4.5 – 4.5.9, 4.6 – 4.6.6, 4.7 – 4.7.5, 4.8 – 4.8.1
Fixed in:
3.7.22
Disclosed:
Sep 19, 2017

CVE-2017-14725 on NVD →

WordPress Core < 4.7.5 - Cross-Site Request Forgery Filesystem Credential Update

high

In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9064 on NVD →

WordPress Core < 4.7.5 - Server-Side Request Forgery

high

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS:
7.7
Affected:
up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9066 on NVD →

WordPress Core < 4.7.5 - Stored Cross-Site Scripting via filenames

medium

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS:
6.4
Affected:
up to 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9061 on NVD →

WordPress Core < 4.7.5 - Mishandling Post Meta Values via XML-RPC

medium

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

CVSS:
6.3
Affected:
up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9062 on NVD →

WordPress Core < 4.7.5 - Cross-Site Scripting via Customizer

medium

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9063 on NVD →

WordPress Core < 4.7.5 - Authorization Bypass Allowing Post Meta Updates

medium

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.20, 3.8 – 3.8.20, 3.9 – 3.9.18, 4.0 – 4.0.17, 4.1 – 4.1.17, 4.2 – 4.2.14, 4.3 – 4.3.10, 4.4 – 4.4.9, 4.5 – 4.5.8, 4.6 – 4.6.5, 4.7 – 4.7.4
Fixed in:
3.7.21
Disclosed:
May 16, 2017

CVE-2017-9065 on NVD →

Wordpress Core < 5.5 - Unauthorized Password Reset via Interception

medium

WordPress up to version 5.5 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the...

CVSS:
5.9
Affected:
up to 5.5
Fixed in:
5.5
Disclosed:
May 3, 2017

CVE-2017-8295 on NVD →

WordPress Core < 4.7.3 - Cross-Site Request Forgery via Press This

high

In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6819 on NVD →

WordPress Core < 4.7.3 - Authenticated Cross-Site Scripting in Youtube URL Embeds

medium

In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6817 on NVD →

WordPress Core < 4.7.3 - Cross-Site Scripting via Media Metadata

medium

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/...

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6814 on NVD →

WordPress Core < 4.7.3 - Cross-Site Scripting via Taxonomy names

medium

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6818 on NVD →

WordPress Core < 4.7.3 - Bypass URL Validation

medium

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6815 on NVD →

WordPress Core < 4.7.3 - Arbitrary File Deletion

medium

In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.

CVSS:
4.9
Affected:
up to 3.7, 3.7 – 3.7.18, 3.8 – 3.8.18, 3.9 – 3.9.16, 4.0 – 4.0.15, 4.1 – 4.1.15, 4.2 – 4.2.12, 4.3 – 4.3.8, 4.4 – 4.4.7, 4.5 – 4.5.6, 4.6 – 4.6.3, 4.7 – 4.7.2
Fixed in:
3.7.19
Disclosed:
Mar 6, 2017

CVE-2017-6816 on NVD →

WordPress Core < 4.7.2 - Authenticated SQL Injection

high

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
Fixed in:
3.7.18
Disclosed:
Jan 26, 2017

CVE-2017-5611 on NVD →

WordPress Core < 4.7.2 - Arbitrary Page Modification

high

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-nu...

CVSS:
7.3
Affected:
up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
Fixed in:
3.7.18
Disclosed:
Jan 26, 2017

CVE-2017-1001000 on NVD →

WordPress Core < 4.7.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
Fixed in:
3.7.18
Disclosed:
Jan 26, 2017

CVE-2017-5612 on NVD →

WordPress Core < 4.7.2 - Authorization Bypass to Term Disclosure

medium

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
Fixed in:
3.7.18
Disclosed:
Jan 26, 2017

CVE-2017-5610 on NVD →

WordPress Core < 4.7.1 - Cross-Site Request Forgery via Widget Editing

high

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets....

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5492 on NVD →

WordPress Core < 4.7.1 - Cross-Site Request Forgery via Uploading Flash File

high

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5489 on NVD →

WordPress Core < 4.7.1 - Authorization Bypass

high

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS:
8.3
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5491 on NVD →

WordPress Core < 4.7.1 - Stored Cross-Site Scripting via theme directory name

medium

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5490 on NVD →

WordPress Core < 4.7.1 - Cross-Site Scripting via Name and Version Header of Plugin

medium

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5488 on NVD →

WordPress Core < 4.7.1 - Weak Multi-Site Activation Key for User and Site Signup

medium

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7.0
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5493 on NVD →

WordPress Core < 4.7.1 - Information Disclosure

medium

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.16, 3.8 – 3.8.16, 3.9 – 3.9.14, 4.0 – 4.0.13, 4.1 – 4.1.13, 4.2 – 4.2.10, 4.3 – 4.3.6, 4.4 – 4.4.5, 4.5 – 4.5.4, 4.6 – 4.6.1, 4.7 – 4.7
Fixed in:
3.7.17
Disclosed:
Jan 11, 2017

CVE-2017-5487 on NVD →

WordPress Core < 4.7.2 - Path Disclosure

medium

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.17, 3.8 – 3.8.17, 3.9 – 3.9.15, 4.0 – 4.0.14, 4.1 – 4.1.14, 4.2 – 4.2.11, 4.3 – 4.3.7, 4.4 – 4.4.6, 4.5 – 4.5.5, 4.6 – 4.6.2, 4.7 – 4.7.1
Fixed in:
3.7.18
Disclosed:
Jan 1, 2017

CVE-2017-6514 on NVD →

WordPress Core < 4.5 - Server-Side Request Forgery

medium

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS:
5
Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Sep 29, 2016

CVE-2016-4029 on NVD →

WordPress Core < 4.6.1 - Authenticated Directory Traversal to Arbitrary File Access

medium

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

CVSS:
6.5
Affected:
up to 3.7, 3.7 – 3.7.15, 3.8 – 3.8.15, 3.9 – 3.9.13, 4.0 – 4.0.12, 4.1 – 4.1.12, 4.2 – 4.2.9, 4.3 – 4.3.5, 4.4 – 4.4.4, 4.5 – 4.5.3, 4.6 – 4.6
Fixed in:
3.7.16
Disclosed:
Sep 7, 2016

CVE-2016-7169 on NVD →

WordPress Core < 4.6.1 - Authenticated Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.

CVSS:
4.8
Affected:
up to 3.7, 3.7 – 3.7.15, 3.8 – 3.8.15, 3.9 – 3.9.13, 4.0 – 4.0.12, 4.1 – 4.1.12, 4.2 – 4.2.9, 4.3 – 4.3.5, 4.4 – 4.4.4, 4.5 – 4.5.3, 4.6 – 4.6
Fixed in:
3.7.16
Disclosed:
Sep 7, 2016

CVE-2016-7168 on NVD →

WordPress Core <= 4.5.3 - Denial of Service

medium

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random...

CVSS:
6.5
Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Aug 22, 2016

CVE-2016-6896 on NVD →

WordPress Core < 4.6 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related...

CVSS:
8.8
Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Aug 16, 2016

CVE-2016-6897 on NVD →

WordPress Core < 4.6 - Authorization Bypass

medium

The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related...

CVSS:
4.3
Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Aug 16, 2016

CVE-2016-10148 on NVD →

WordPress Core < 4.5.3 - Bypass sanitize_file_name Protection

high

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.

CVSS:
7.3
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5839 on NVD →

WordPress Core < 4.5.3 - Cross-Site Scripting via Attachment Name

medium

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5834 on NVD →

WordPress Core < 4.5.3 - Cross-Site Scripting via Attachment Name #2

medium

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5833 on NVD →

WordPress Core < 4.5.3 - Cross-Site Scripting via Customizer

medium

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5832 on NVD →

WordPress Core < 4.5.3 - Authorization Bypass to Remove Category Attribute

medium

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5837 on NVD →

WordPress Core < 4.5.3 - Denial of Service via oEmbed Protocol

medium

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5836 on NVD →

WordPress Core < 4.5.3 - Password Change via Stolen Cookie

medium

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5838 on NVD →

WordPress Core < 4.5.3 - Revision History Disclosure

medium

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.14, 3.8 – 3.8.14, 3.9 – 3.9.12, 4.0 – 4.0.11, 4.1 – 4.1.11, 4.2 – 4.2.8, 4.3 – 4.3.4, 4.4 – 4.4.3, 4.5 – 4.5.2
Fixed in:
3.7.15
Disclosed:
Jun 18, 2016

CVE-2016-5835 on NVD →

WordPress Core < 4.5.2 - Cross-Site Scripting via MediaElement.js

medium

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.13, 3.8 – 3.8.13, 3.9 – 3.9.11, 4.0 – 4.0.10, 4.1 – 4.1.10, 4.2 – 4.2.7, 4.3 – 4.3.3, 4.4 – 4.4.2, 4.5 – 4.5.1
Fixed in:
3.7.14
Disclosed:
May 6, 2016

CVE-2016-4567 on NVD →

WordPress Core < 4.5.2 - Cross-Site Scripting via plupload.flash.swf

medium

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.13, 3.8 – 3.8.13, 3.9 – 3.9.11, 4.0 – 4.0.10, 4.1 – 4.1.10, 4.2 – 4.2.7, 4.3 – 4.3.3, 4.4 – 4.4.2, 4.5 – 4.5.1
Fixed in:
3.7.14
Disclosed:
May 6, 2016

CVE-2016-4566 on NVD →

WordPress Core < 4.5 - Cross-Site Scripting via Network Settings Page

medium

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.4
Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Apr 12, 2016

CVE-2016-6634 on NVD →

WordPress Core < 4.5 - Cross-Site Request Forgery via wp_ajax_wp_compression_test

high

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS:
8.8
Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Mar 12, 2016

CVE-2016-6635 on NVD →

WordPress Core < 4.4.2 - Server-Side Request Forgery

medium

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.12, 3.8 – 3.8.12, 3.9 – 3.9.10, 4.0 – 4.0.9, 4.1 – 4.1.9, 4.2 – 4.2.6, 4.3 – 4.3.2, 4.4 – 4.4.1
Fixed in:
3.7.13
Disclosed:
Feb 2, 2016

CVE-2016-2222 on NVD →

WordPress Core < 4.4.2 - Open Redirect via wp_validate_redirect

medium

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.12, 3.8 – 3.8.12, 3.9 – 3.9.10, 4.0 – 4.0.9, 4.1 – 4.1.9, 4.2 – 4.2.6, 4.3 – 4.3.2, 4.4 – 4.4.1
Fixed in:
3.7.13
Disclosed:
Feb 2, 2016

CVE-2016-2221 on NVD →

WordPress Core < 4.4.1 - Cross-Site Scripting via Theme Names

medium

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.11, 3.8 – 3.8.11, 3.9 – 3.9.9, 4.0 – 4.0.8, 4.1 – 4.1.8, 4.2 – 4.2.5, 4.3 – 4.3.1, 4.4 – 4.4
Fixed in:
3.7.12
Disclosed:
Jan 16, 2016

CVE-2016-1564 on NVD →

WordPress Core < 4.3.1 - Authenticated Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
Fixed in:
3.7.11
Disclosed:
Sep 15, 2015

CVE-2015-7989 on NVD →

WordPress Core < 4.3.1 - Cross-Site Scripting via Shortcodes

medium

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
Fixed in:
3.7.11
Disclosed:
Sep 15, 2015

CVE-2015-5714 on NVD →

WordPress Core < 4.3.1 - Authorization Bypass to Information Disclosure

medium

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.10, 3.8 – 3.8.10, 3.9 – 3.9.8, 4.0 – 4.0.7, 4.1 – 4.1.7, 4.2 – 4.2.4, 4.3 – 4.3
Fixed in:
3.7.11
Disclosed:
Sep 15, 2015

CVE-2015-5715 on NVD →

WordPress Core < 4.2.4 - Cross-Site Request Forgery to Post Lockage

critical

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS:
9.6
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-5731 on NVD →

WordPress Core < 4.2.4 - SQL Injection

high

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-2213 on NVD →

WordPress Core < 4.2.4 - Cross-Site Scripting in Theme Preview

medium

Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.

CVSS:
6.1
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-5734 on NVD →

WordPress Core < 4.2.4 - Cross-Site Scripting via Widget Title

medium

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVSS:
5.5
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-5732 on NVD →

WordPress Core < 4.2.4 - Stored Cross-Site Scripting via accessibility-helper Title

medium

Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-5733 on NVD →

WordPress Core < 4.2.4 - Timing Side-Channel Attack

medium

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.9, 3.8 – 3.8.9, 3.9 – 3.9.7, 4.0 – 4.0.6, 4.1 – 4.1.6, 4.2 – 4.2.3
Fixed in:
3.7.10
Disclosed:
Aug 4, 2015

CVE-2015-5730 on NVD →

WordPress Core < 4.2.3 - Authorization Bypass

medium

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS:
6.5
Affected:
up to 3.7, 3.7 – 3.7.8, 3.8 – 3.8.8, 3.9 – 3.9.6, 4.0 – 4.0.5, 4.1 – 4.1.5, 4.2 – 4.2.2
Fixed in:
3.7.9
Disclosed:
Jul 23, 2015

CVE-2015-5623 on NVD →

WordPress Core < 4.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.8, 3.8 – 3.8.8, 3.9 – 3.9.6, 4.0 – 4.0.5, 4.1 – 4.1.5, 4.2 – 4.2.2
Fixed in:
3.7.9
Disclosed:
Jul 23, 2015

CVE-2015-5622 on NVD →

WordPress Core < 4.2.2 - Cross-Site Scripting via Comments

high

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CV...

CVSS:
7.2
Affected:
up to 3.7, 3.7 – 3.7.7, 3.8 – 3.8.7, 3.9 – 3.9.5, 4.0 – 4.0.4, 4.1 – 4.1.4, 4.2 – 4.2.1
Fixed in:
3.7.8
Disclosed:
May 7, 2015

CVE-2015-8834 on NVD →

WordPress Core < 4.2.1 - Cross-Site Scripting via Comments

high

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS:
7.2
Affected:
4.0 – 4.0.3, 4.1 – 4.1.3, 4.2 – 4.2
Fixed in:
4.0.4
Disclosed:
Apr 27, 2015

CVE-2015-3440 on NVD →

WordPress Core < 4.1.2 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a c...

CVSS:
7.2
Affected:
up to 3.7, 3.7 – 3.7.5, 3.8 – 3.8.5, 3.9 – 3.9.3, 4.0 – 4.0.1, 4.1 – 4.1.1
Fixed in:
3.7.6
Disclosed:
Apr 21, 2015

CVE-2015-3438 on NVD →

WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload

medium

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a...

CVSS:
5.4
Affected:
up to 3.7, 3.7 – 3.7.5, 3.8 – 3.8.5, 3.9 – 3.9.3, 4.0 – 4.0.1, 4.1 – 4.1.1
Fixed in:
3.7.6
Disclosed:
Apr 20, 2015

CVE-2015-3439 on NVD →

Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 - Cross-Site Scripting via example.html

medium

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.7, 3.8 – 3.8.7, 3.9 – 3.9.5, 4.0 – 4.0.4, 4.1 – 4.1.4, 4.2 – 4.2.1
Fixed in:
3.7.8
Disclosed:
Apr 8, 2015

CVE-2015-3429 on NVD →

WordPress Core < 4.4 - Brute Force Password Recovery Tokens

high

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS:
7.5
Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Feb 12, 2015

CVE-2014-6412 on NVD →

WordPress Core < 4.0.1 Cross-Site Request Forgery to Password Reset

high

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9039 on NVD →

Wordpress Core < 4.0.1 - Hash Collision

high

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS:
8.1
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9037 on NVD →

WordPress Core < 4.0.1 - Server-Side Request Forgery

high

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS:
7.7
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9038 on NVD →

WordPress Core < 4.0.1 - Cross-Site Scripting via media-playlists

high

Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
7.2
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9032 on NVD →

WordPress Core < 4.0.1 - Cross-Site Scripting via CSS

medium

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

CVSS:
6.4
Affected:
up to 3.6.1, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9036 on NVD →

WordPress Core < 4.0.1 - Cross-Site Scripting via Shortcode Brackets

medium

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9031 on NVD →

WordPress Core < 4.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.4
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9035 on NVD →

WordPress Core < 4.0.1 - Denial of Service via Long Password

medium

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS:
5.3
Affected:
up to 3.7, 3.7 – 3.7.4, 3.8 – 3.8.4, 3.9 – 3.9.2, 4.0 – 4.0
Fixed in:
3.7.5
Disclosed:
Nov 20, 2014

CVE-2014-9034 on NVD →

WordPress Core < 3.9.2 - Cross-Site Request Forgery Protection Bypass

high

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5204 on NVD →

WordPress Core < 4.0.1 - Cross-Site Request Forgery to Authentication Takeover

high

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS:
8.8
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-9033 on NVD →

WordPress Core < 3.9.2 - Deserialization via Widgets

high

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

CVSS:
7.2
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5203 on NVD →

WordPress Core < 3.9.2 - Brute Force of Cross-Site Request Forgery Tokens

medium

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS:
6.5
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5205 on NVD →

WordPress Core < 3.9.2 - Denial of Service via XML #2

medium

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS:
6.5
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5266 on NVD →

WordPress Core <= 3.9.1 - XML External Entity (XXE) Weakness

medium

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

CVSS:
5.3
Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Aug 6, 2014

CVE-2014-2053 on NVD →

WordPress Core < 3.9.2 - Authenticated Cross-Site Scripting via Avatar URL

low

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

CVSS:
3.8
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5240 on NVD →

WordPress Core < 3.9.2 - Denial of Service via XML

low

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document conta...

CVSS:
2.7
Affected:
up to 3.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.1
Fixed in:
3.7.4
Disclosed:
Aug 6, 2014

CVE-2014-5265 on NVD →

WordPress Core < 3.8.2 - SQL Injection

high

WordPress Core, in versions less than 3.8.2, is vulnerable to SQL Injection via the 'links_recently_updated_time' parameter. This can only be exploited by administrative users and above.

CVSS:
7.2
Affected:
3.8.1 – 3.8.1
Fixed in:
3.8.2
Disclosed:
Apr 9, 2014

WordPress Core < 3.8.2 - Authentication Cookie Forgery

medium

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS:
6.5
Affected:
up to 3.7, 3.7 – 3.7.1, 3.8 – 3.8.1
Fixed in:
3.7.2
Disclosed:
Apr 8, 2014

CVE-2014-0166 on NVD →

WordPress Core < 3.8.2 - Contributor Users Can Publish Posts

medium

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS:
4.3
Affected:
up to 3.7, 3.7 – 3.7.1, 3.8 – 3.8.1
Fixed in:
3.7.2
Disclosed:
Apr 8, 2014

CVE-2014-0165 on NVD →

WordPress Core < 2.1 - Cross-Site Request Forgery to Denial of Service

high

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS:
8.8
Affected:
up to 2.0.11
Fixed in:
2.1
Disclosed:
Dec 17, 2013

CVE-2013-7233 on NVD →

WordPress Core < 3.6.1 - Deserialization

high

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

CVSS:
8.8
Affected:
up to 3.6
Fixed in:
3.6.1
Disclosed:
Sep 11, 2013

CVE-2013-4338 on NVD →

WordPress Core < 3.6.1 - HTML File Upload

medium

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS:
6.4
Affected:
up to 3.6
Fixed in:
3.6.1
Disclosed:
Sep 11, 2013

CVE-2013-5738 on NVD →

WordPress Core < 3.6.1 - .swf and .exe File Upload

medium

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS:
6.4
Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Sep 11, 2013

CVE-2013-5739 on NVD →

WordPress Core < 3.6.1 - Spoof Post Authorship

medium

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS:
6.3
Affected:
up to 3.6
Fixed in:
3.6.1
Disclosed:
Sep 11, 2013

CVE-2013-4340 on NVD →

WordPress Core < 3.6.1 - Open Redirect

medium

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS:
5.4
Affected:
up to 3.6
Fixed in:
3.6.1
Disclosed:
Sep 11, 2013

CVE-2013-4339 on NVD →

WordPress Core < 3.5.2 - Cross-Site Scripting via Multiple Vectors

medium

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to the...

CVSS:
6.4
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2201 on NVD →

WordPress Core < 3.5.2 - Cross-Site Scripting

medium

The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS:
6.4
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2205 on NVD →

WordPress Core < 3.5.2 - Missing Authorization Checks

medium

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

CVSS:
6.3
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2200 on NVD →

WordPress Core < 3.5.2 - XXE Injection

medium

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS:
5.4
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2202 on NVD →

WordPress Core < 3.5.2 - Server Side Request Forgery

medium

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS:
5.4
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2199 on NVD →

WordPress Core <= 3.5.1 - Denial of Service via wp-postpass cookie

medium

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

CVSS:
5.3
Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2173 on NVD →

WordPress Core <= 3.5.1 - Content-Spoofing Attacks

medium

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct co...

CVSS:
4.6
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2204 on NVD →

WordPress Core < 3.5.2 - Sensitive Information Disclosure

medium

WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.

CVSS:
4.3
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 21, 2013

CVE-2013-2203 on NVD →

WordPress Core < 3.5.1 - Stored Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS:
6.4
Affected:
up to 3.5.1
Fixed in:
3.5.1
Disclosed:
Jan 24, 2013

CVE-2013-0236 on NVD →

WordPress Core < 3.5.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS:
6.4
Affected:
up to 3.5
Fixed in:
3.5.1
Disclosed:
Jan 24, 2013

CVE-2013-0237 on NVD →

WordPress Core < 3.5.1 - Server-Side Request Forgery

medium

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS:
5.4
Affected:
up to 3.5
Fixed in:
3.5.1
Disclosed:
Jan 24, 2013

CVE-2013-0235 on NVD →

WordPress Core < 4.0 - Missing Session Cookie Expiration

medium

WordPress Core before 4.0 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS:
5.4
Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Dec 27, 2012

CVE-2012-5868 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

WordPress Core < 3.4.2 - Cross-Site Scripting

medium

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leve...

CVSS:
6.4
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Sep 6, 2012

CVE-2012-3383 on NVD →

WordPress Core < 3.4.2 - Missing Authorization Checks on create_post

medium

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) fea...

CVSS:
6.3
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Sep 6, 2012

CVE-2012-4421 on NVD →

WordPress Core < 3.4.2 - Missing Authorization Checks

low

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator ro...

CVSS:
3.8
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Sep 6, 2012

CVE-2012-4422 on NVD →

WordPress Core < 3.4.1 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS:
8.8
Affected:
up to 3.4
Fixed in:
3.4.1
Disclosed:
Jun 27, 2012

CVE-2012-3384 on NVD →

WordPress Core <= 3.3.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS:
6.5
Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Jun 27, 2012

CVE-2012-6633 on NVD →

WordPress Core <= 3.3.2 - Sensitive Information Disclosure

medium

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS:
5.3
Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Jun 27, 2012

CVE-2012-6634 on NVD →

WordPress Core <= 3.3.2 - Sensitive Information Disclosure

medium

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS:
4.3
Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Jun 27, 2012

CVE-2012-6635 on NVD →

WordPress Core < 3.4.1 - Information Disclosure

medium

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS:
4.3
Affected:
up to 3.4
Fixed in:
3.4.1
Disclosed:
Jun 27, 2012

CVE-2012-3385 on NVD →

WordPress Core - Informational < 6.8 - Weak Hashing Algorithm

low

Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a Wor...

CVSS:
3.7
Affected:
up to 6.8
Fixed in:
6.8
Disclosed:
Jun 20, 2012

CVE-2012-6707 on NVD →

WordPress Core <= 3.5.1 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-34...

CVSS:
7.2
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Apr 21, 2012

CVE-2012-2399 on NVD →

WordPress Core <= 3.3.1 - Cross-Site Scripting

medium

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS:
5.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 21, 2012

CVE-2012-2404 on NVD →

WordPress Core < 3.3.2 - Cross-Site Scripting

high

Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

CVSS:
7.2
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 20, 2012

CVE-2012-2400 on NVD →

WordPress Core <= 3.3.1 - Same Origin Policy Bypass

medium

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.

CVSS:
6.5
Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Apr 20, 2012

CVE-2012-2401 on NVD →

WordPress Core < 3.3.2 - Cross-Site Scripting

medium

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS:
6.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 20, 2012

CVE-2012-2403 on NVD →

WordPress Core <= 3.3.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
5.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 20, 2012

CVE-2012-3414 on NVD →

WordPress Core < 3.3.2 - Authorization Bypass

medium

wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.

CVSS:
5.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 20, 2012

CVE-2012-2402 on NVD →

WordPress Core <= 3.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.

CVSS:
6.4
Affected:
up to 3.3
Fixed in:
3.3.1
Disclosed:
Jan 3, 2012

CVE-2012-0287 on NVD →

WordPress Core <= 3.1.2 - Arbitrary File Upload

high

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

CVSS:
8.8
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3129 on NVD →

WordPress Core <= 3.1.2 - SQL Injection

high

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

CVSS:
8.8
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3130 on NVD →

WordPress Core < 3.1.3 - Clickjacking

high

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS:
7.1
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3127 on NVD →

WordPress Core < 3.1.3 - Media Related Security Issue

medium

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS:
6.3
Affected:
up to 3.1.2
Fixed in:
3.2
Disclosed:
May 25, 2011

CVE-2011-3122 on NVD →

WordPress Core < 3.1.3 - Security Hardening

medium

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS:
6.3
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3125 on NVD →

WordPress Core < 3.1.3 - Username Enumeration

medium

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS:
5.3
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3126 on NVD →

WordPress Core < 3.1.3 - Sensitive Information Disclosure

medium

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

CVSS:
4.3
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 25, 2011

CVE-2011-3128 on NVD →

WordPress Core < 3.0.6 - Incorrect Authorization Checks

medium

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

CVSS:
6.3
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Apr 26, 2011

CVE-2011-5270 on NVD →

WordPress Core < 3.1.2 - Incorrect Authorization for Contributor-level users

medium

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS:
4.3
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Apr 26, 2011

CVE-2011-1762 on NVD →

WordPress Core < 3.1.1 - Denial of Service

high

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.

CVSS:
7.5
Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Apr 5, 2011

CVE-2011-4957 on NVD →

WordPress Core <= 3.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.4
Affected:
up to 3.1
Fixed in:
3.1.1
Disclosed:
Apr 5, 2011

CVE-2011-4956 on NVD →

WordPress Core < 3.0.5 - Improper Authorization to Information Disclosure

medium

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS:
4.3
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Feb 7, 2011

CVE-2011-0701 on NVD →

WordPress Core 2.9.2 and 3.0.4 - Sensitive Information Disclosure

high

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

CVSS:
7.5
Affected:
2.9.2 – 2.9.2, 3.0.4 – 3.0.4
Fixed in:
3.0
Disclosed:
Jan 28, 2011

CVE-2011-3818 on NVD →

WordPress Core < 3.0.2 - Missing Authorization

medium

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS:
5.4
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Dec 30, 2010

CVE-2010-5296 on NVD →

WordPress Core <= 3.0.3 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS:
6.4
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Dec 29, 2010

CVE-2010-4536 on NVD →

WordPress Core < 3.0.3 - Access Control Bypass

medium

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS:
6.3
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Dec 8, 2010

CVE-2010-5106 on NVD →

WordPress Core <= 3.0.1 - SQL Injection

high

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS:
8.8
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Nov 30, 2010

CVE-2010-4257 on NVD →

WordPress Core < 3.0.2 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS:
6.4
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Nov 30, 2010

CVE-2010-5294 on NVD →

WordPress Core < 3.0.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS:
6.4
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Nov 30, 2010

CVE-2010-5295 on NVD →

WordPress Core < 3.0.2 - Spam Protection Bypass

medium

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS:
5.3
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Nov 30, 2010

CVE-2010-5293 on NVD →

WordPress Core < 3.0.1 - Missing Authorization

medium

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS:
4.7
Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Jul 29, 2010

CVE-2010-5297 on NVD →

WordPress Core < 2.9.2 - Authorization Bypass

medium

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS:
4.3
Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Feb 15, 2010

CVE-2010-0682 on NVD →

WordPress Core <= 2.8.5 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-...

CVSS:
8.8
Affected:
up to 2.8.5
Fixed in:
2.8.6
Disclosed:
Dec 12, 2009

CVE-2009-3890 on NVD →

WordPress Core <= 2.8.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

CVSS:
6.4
Affected:
up to 2.8.5
Fixed in:
2.8.6
Disclosed:
Dec 12, 2009

CVE-2009-3891 on NVD →

WordPress Core <= 2.8.4 - Denial of Service

medium

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_enco...

CVSS:
6.5
Affected:
up to 2.8.4
Fixed in:
2.8.5
Disclosed:
Oct 20, 2009

CVE-2009-3622 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Full Path Disclosure

medium

WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Sep 8, 2009

CVE-2009-2432 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Full Path Disclosure

medium

WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Sep 8, 2009

CVE-2009-2432 on NVD →

WordPress Core < 2.8.4 - Forced Password Reset

high

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

CVSS:
7.5
Affected:
up to 2.8.3
Fixed in:
2.8.4
Disclosed:
Aug 12, 2009

CVE-2009-2762 on NVD →

WordPress Core < 2.8.3 - Missing Authorization

high

Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.ph...

CVSS:
7.3
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Aug 3, 2009

CVE-2009-2854 on NVD →

WordPress Core < 2.8.3 - Authorization Bypass

high

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

CVSS:
7.3
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Aug 3, 2009

CVE-2009-2853 on NVD →

WordPress Core <= 2.8.1 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.

CVSS:
7.2
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jul 20, 2009

CVE-2009-2851 on NVD →

WordPress Core <= 2.8 - Sensitive Information Disclosure

medium

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collap...

CVSS:
6.1
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2334 on NVD →

WordPress Core <= 2.8 - Sensitive Information Disclosure

medium

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collap...

CVSS:
6.1
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2334 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Username Enumeration

medium

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user conv...

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2335 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Username Enumeration

medium

The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the b...

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2336 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Username Enumeration

medium

The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the b...

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2336 on NVD →

WordPress Core & WordPress MU < 2.8.1 - Username Enumeration

medium

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user conv...

CVSS:
5.3
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Jul 9, 2009

CVE-2009-2335 on NVD →

WordPress Core < 2.8 - Sensitive Information Disclosure

medium

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

CVSS:
5.3
Affected:
up to 2.7.1
Fixed in:
2.8
Disclosed:
Jun 11, 2009

CVE-2009-2431 on NVD →

WordPress MU < 2.7 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS:
6.4
Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Mar 10, 2009

CVE-2009-1030 on NVD →

WordPress Core < 2.6.5 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVSS:
7.2
Affected:
up to 2.6.4
Fixed in:
2.6.5
Disclosed:
Dec 25, 2008

CVE-2008-5278 on NVD →

WordPress Core < 2.8.1 - Open Redirect

medium

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS:
6.1
Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Dec 22, 2008

CVE-2008-6762 on NVD →

WordPress Core < 2.7 - Denial of Service

medium

wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request if WordPress is not yet setup by creating an empty database, which will prevent future installations from succeeding.

CVSS:
5.3
Affected:
up to 2.6.1
Fixed in:
2.7
Disclosed:
Dec 22, 2008

CVE-2008-6767 on NVD →

WordPress Core < 2.6.2 - Arbitrary User Password Reset

high

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value...

CVSS:
8.1
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Sep 8, 2008

CVE-2008-4106 on NVD →

WordPress Core < 2.6.2 - Cryptographic Weakness

medium

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before...

CVSS:
6.5
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Sep 8, 2008

CVE-2008-4107 on NVD →

WordPress MU < 2.6 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.

CVSS:
6.4
Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Sep 1, 2008

CVE-2008-4671 on NVD →

WordPress Core < 2.6.1 - Cryptographic Weakness

medium

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

CVSS:
5.9
Affected:
up to 2.6
Fixed in:
2.6.1
Disclosed:
Aug 15, 2008

CVE-2008-3747 on NVD →

WordPress Core < 2.6 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
7.2
Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 15, 2008

CVE-2008-3233 on NVD →

WordPress Core < 2.5.1 - Authentication Bypass

high

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtai...

CVSS:
8.1
Affected:
up to 2.5
Fixed in:
2.5.1
Disclosed:
Apr 25, 2008

CVE-2008-1930 on NVD →

WordPress Core <= 2.3.3 - Directory Traversal

high

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information...

CVSS:
7.5
Affected:
up to 2.3.3, 2.5 – 2.5
Fixed in:
2.5.1
Disclosed:
Apr 25, 2008

CVE-2008-4769 on NVD →

WordPress Core <= 2.5.1 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.

CVSS:
7.2
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Apr 25, 2008

CVE-2008-2392 on NVD →

WordPress Core <= 2.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.4
Affected:
up to 2.5
Fixed in:
2.5.1
Disclosed:
Apr 25, 2008

CVE-2008-2068 on NVD →

WordPress Core <= 2.3.2 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.

CVSS:
6.4
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Feb 5, 2008

CVE-2008-1304 on NVD →

WordPress Core 1.5 - 2.3.1 - Authorization Bypass

critical

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

CVSS:
9.8
Affected:
1.5 – 2.3.1
Fixed in:
2.3.2
Disclosed:
Dec 29, 2007

CVE-2007-6013 on NVD →

WordPress Core < 2.5 - Full Path Disclosure

medium

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.

CVSS:
5.3
Affected:
up to 2.4
Fixed in:
2.5
Disclosed:
Dec 16, 2007

CVE-2008-0191 on NVD →

WordPress Core <= 2.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.

CVSS:
6.4
Affected:
up to 2.3
Fixed in:
2.3.1
Disclosed:
Oct 26, 2007

CVE-2007-5710 on NVD →

WordPress Core < 2.0.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.

CVSS:
6.4
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Sep 21, 2007

CVE-2007-5106 on NVD →

WordPress Core < 2.3.2 - SQL Injection

critical

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.

CVSS:
9.8
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Sep 8, 2007

CVE-2007-6318 on NVD →

WordPress Core < 2.2.3 & WordPress MU < 1.2.5a - SQL Injection

critical

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early dat...

CVSS:
9.8
Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Sep 8, 2007

CVE-2007-4894 on NVD →

WordPress Core < 2.2.3 & WordPress MU < 1.2.5a - SQL Injection

critical

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early dat...

CVSS:
9.8
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Sep 8, 2007

CVE-2007-4894 on NVD →

WordPress Core < 2.3.3 & WordPress MU < 1.3.2 - Remote Code Execution

high

wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to...

CVSS:
8.8
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Sep 8, 2007

CVE-2008-5695 on NVD →

WordPress Core < 2.3.3 & WordPress MU < 1.3.2 - Remote Code Execution

high

wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to...

CVSS:
8.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Sep 8, 2007

CVE-2008-5695 on NVD →

WordPress Core < 2.3.3 - Improper Authorization Checks

medium

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.

CVSS:
6.5
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Sep 8, 2007

CVE-2008-0664 on NVD →

WordPress Core < 2.2.3 - Restriction Bypass

medium

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

CVSS:
5.3
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Sep 8, 2007

CVE-2008-2146 on NVD →

WordPress MU <= 1.0 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).

CVSS:
6.1
Affected:
up to 1.0
Fixed in:
1.1.1
Disclosed:
Aug 22, 2007

CVE-2007-4544 on NVD →

WordPress Core < 2.2.2 - Open Redirect

medium

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.p...

CVSS:
6.1
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Aug 8, 2007

CVE-2007-3639 on NVD →

WordPress Core <= 2.2.1 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts....

CVSS:
8.8
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Aug 5, 2007

CVE-2007-3544 on NVD →

WordPress Core <= 2.2 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID...

CVSS:
8.8
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Aug 5, 2007

CVE-2007-3543 on NVD →

WordPress Core <= 2.2.1 - SQL Injection

high

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permali...

CVSS:
8.8
Affected:
up to 2.0.10, 2.2 – 2.2.1
Fixed in:
2.0.11
Disclosed:
Aug 5, 2007

CVE-2007-4154 on NVD →

WordPress Core <= 2.2.1 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts....

CVSS:
8.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Aug 5, 2007

CVE-2007-3544 on NVD →

WordPress Core <= 2.2.2 - Cross-Site Scripting

medium

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

CVSS:
6.4
Affected:
up to 1.2.5a
Fixed in:
1.2.5a
Disclosed:
Aug 5, 2007

CVE-2007-4893 on NVD →

WordPress Core <= 2.2.2 - Cross-Site Scripting

medium

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

CVSS:
6.4
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Aug 5, 2007

CVE-2007-4893 on NVD →

WordPress Core <= 2.2.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php.

CVSS:
6.4
Affected:
up to 2.0.10, 2.2 – 2.2.1
Fixed in:
2.0.11
Disclosed:
Aug 5, 2007

CVE-2007-4139 on NVD →

WordPress Core <= 2.2.1 - Authenticated (Admin+) Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privi...

CVSS:
5.5
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Aug 5, 2007

CVE-2007-4153 on NVD →

WordPress Core <= 2.2 - SQL Injection

high

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVSS:
8.8
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Jun 21, 2007

CVE-2007-3140 on NVD →

WordPress Core <= 2.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

CVSS:
6.1
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Jun 21, 2007

CVE-2007-2627 on NVD →

WordPress Core < 2.1.3 - SQL Injection

high

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVSS:
8.8
Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Apr 3, 2007

CVE-2007-1897 on NVD →

WordPress Core <= 2.0.9 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.

CVSS:
7.2
Affected:
up to 2.0.9
Fixed in:
2.0.10
Disclosed:
Apr 3, 2007

CVE-2008-0192 on NVD →

WordPress Core <= 2.1.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.

CVSS:
6.4
Affected:
up to 2.0.9, 2.1 – 2.1.2
Fixed in:
2.0.10
Disclosed:
Apr 3, 2007

CVE-2007-1894 on NVD →

WordPress Core < 2.0.10 - Open Redirect

medium

wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.

CVSS:
6.1
Affected:
up to 2.0.10
Fixed in:
2.0.10
Disclosed:
Apr 3, 2007

CVE-2007-1599 on NVD →

WordPress Core <= 2.1.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression proc...

CVSS:
6.1
Affected:
up to 2.0.9, 2.1 – 2.1.1
Fixed in:
2.0.10
Disclosed:
Apr 3, 2007

CVE-2007-1622 on NVD →

WordPress Core < 2.1.3 - Authorization Bypass

medium

xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."

CVSS:
4.3
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Apr 3, 2007

CVE-2007-1893 on NVD →

WordPress Core 2.2.1 - Backdoor

critical

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru ca...

CVSS:
9.8
Affected:
2.2.1 – 2.2.1
Fixed in:
2.2.2
Disclosed:
Mar 3, 2007

CVE-2007-1277 on NVD →

WordPress Core 2.1.1 - Supply Chain Compromise

critical

Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress sites.

CVSS:
9.8
Affected:
2.1.1 – 2.1.1
Fixed in:
2.1.2
Disclosed:
Mar 2, 2007

WordPress Core <= 2.1.1 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS:
6.4
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Mar 2, 2007

CVE-2007-1230 on NVD →

WordPress Core <= 2.1.1 - Cross-Site Scripting

medium

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and ste...

CVSS:
6.4
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Mar 2, 2007

CVE-2007-1244 on NVD →

WordPress Core < 2.09 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vec...

CVSS:
7.2
Affected:
up to 2.0.9, 2.1 – 2.1
Fixed in:
2.0.9
Disclosed:
Feb 21, 2007

CVE-2007-1049 on NVD →

WordPress Core <= 3.0.4 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within...

CVSS:
6.4
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Feb 11, 2007

CVE-2011-0700 on NVD →

WordPress Core < 2.1 - Directory Traversal

medium

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes...

CVSS:
6.5
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jan 24, 2007

CVE-2007-0541 on NVD →

WordPress Core < 2.1 - Full Path Disclosure

medium

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.

CVSS:
5.3
Affected:
up to 2.0.11
Fixed in:
2.1
Disclosed:
Jan 22, 2007

CVE-2008-0195 on NVD →

WordPress Core < 2.1 - Denial of Service

medium

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS:
4.3
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jan 22, 2007

CVE-2007-0539 on NVD →

WordPress Core < 2.0.7 - SQL Injection

high

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vu...

CVSS:
8.8
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Jan 15, 2007

CVE-2007-0233 on NVD →

WordPress Core < 2.0.7 - Full Path Disclosure

medium

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS:
5.3
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Jan 15, 2007

CVE-2007-0262 on NVD →

WordPress Core <= 2.0.5 - SQL Injection

critical

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.

CVSS:
9.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 5, 2007

CVE-2007-0107 on NVD →

WordPress Core <= 2.0.5 - Cross-Site Request Forgery to Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new l...

CVSS:
8.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 5, 2007

CVE-2007-0106 on NVD →

WordPress Core <= 2.0.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 5, 2007

CVE-2006-6808 on NVD →

WordPress < 2.0.6 - Username Enumeration via Error Messages

medium

wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

CVSS:
5.3
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 5, 2007

CVE-2007-0109 on NVD →

WordPress Core 2.0.2 - 2.0.5 - Sensitive Information Disclosure

medium

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) heade...

CVSS:
5.3
Affected:
2.0.2 – 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 5, 2007

CVE-2006-4743 on NVD →

WordPress Core <= 2.0.4 - Directory Traversal

medium

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.

CVSS:
6.5
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Oct 27, 2006

CVE-2006-5705 on NVD →

WordPress Core <= 2.0.4 - Denial of Service

medium

WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic...

CVSS:
6.5
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Oct 27, 2006

CVE-2006-6017 on NVD →

WordPress Core < 2.0.5 - User Metadata Information Disclosure

medium

wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.

CVSS:
4.3
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Sep 18, 2006

CVE-2006-6016 on NVD →

WordPress Core < 1.5.2 - Full Path Disclosure

medium

WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error...

CVSS:
5.3
Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Aug 14, 2006

CVE-2005-4463 on NVD →

WordPress Core <= 2.0.3 - Denial of Service

medium

Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2...

CVSS:
6.5
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Jul 29, 2006

CVE-2008-0194 on NVD →

WordPress Core < 2.0.4 - Full Path Disclosure

medium

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS:
5.3
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Jul 29, 2006

CVE-2006-3390 on NVD →

WordPress Core < 2.0.4 - Privilege Escalation

critical

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can registe...

CVSS:
9.8
Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Jul 9, 2006

CVE-2006-4028 on NVD →

WordPress Core < 2.0.3 - Remote Code Execution

high

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/user...

CVSS:
8.8
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jun 1, 2006

CVE-2006-2667 on NVD →

WordPress Core < 2.0.3 - IP Address Spoofing

medium

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].

CVSS:
5.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jun 1, 2006

CVE-2006-2702 on NVD →

WordPress Core < 2.0.2 - Sensitive Information Disclosure

high

WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9)...

CVSS:
7.5
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Mar 10, 2006

CVE-2006-0986 on NVD →

WordPress Core <= 2.0.1 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.

CVSS:
7.2
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Mar 10, 2006

CVE-2006-0985 on NVD →

WordPress Core < 2.0.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.

CVSS:
6.1
Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Mar 10, 2006

CVE-2007-5105 on NVD →

WordPress Core < 2.0.2 - Reflected Cross-Site Scripting

medium

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS:
6.1
Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Mar 10, 2006

CVE-2006-1263 on NVD →

WordPress Core < 2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

CVSS:
6.1
Affected:
up to 2.0
Fixed in:
2.0.1
Disclosed:
Jan 31, 2006

CVE-2006-1796 on NVD →

WordPress Core <= 1.5.2 - SQL Injection

high

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

CVSS:
7.2
Affected:
up to 1.5.2
Fixed in:
2.0
Disclosed:
Dec 31, 2005

CVE-2006-1012 on NVD →

WordPress Core < 1.5.2 - Remote Code Execution

high

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

CVSS:
8.8
Affected:
up to 1.5.1.3
Fixed in:
1.5.2
Disclosed:
Aug 9, 2005

CVE-2005-2612 on NVD →

WordPress Core < 1.5.1.3 - SQL Injection

high

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

CVSS:
8.8
Affected:
up to 1.5.1.3
Fixed in:
1.5.1.3
Disclosed:
Jun 29, 2005

CVE-2005-2108 on NVD →

WordPress Core < 1.5.1.3 - Sensitive Information Disclosure

high

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect Wo...

CVSS:
7.3
Affected:
up to 1.5.1.2
Fixed in:
1.5.1.3
Disclosed:
Jun 29, 2005

CVE-2005-2110 on NVD →

WordPress Core <= 1.5.1.2 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVSS:
7.2
Affected:
up to 1.5.1.2
Fixed in:
1.5.1.3
Disclosed:
Jun 29, 2005

CVE-2005-2107 on NVD →

WordPress Core < 1.5.1.3 - Arbitrary Email Content Change

medium

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.

CVSS:
5.3
Affected:
up to 1.5.1.2
Fixed in:
1.5.1.3
Disclosed:
Jun 29, 2005

CVE-2005-2109 on NVD →

WordPress Core <= 1.5 - Stored Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.

CVSS:
6.4
Affected:
up to 1.5.1
Fixed in:
1.5.1.2
Disclosed:
Jun 27, 2005

CVE-2005-1102 on NVD →

WordPress Core < 1.5.1.2 - SQL Injection

high

SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.

CVSS:
8.8
Affected:
up to 1.5.1.1
Fixed in:
1.5.1.2
Disclosed:
May 27, 2005

CVE-2005-1810 on NVD →

WordPress Core < 1.5.1 - SQL Injection

high

SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.

CVSS:
8.8
Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
May 9, 2005

CVE-2005-1687 on NVD →

WordPress Core < 1.5.1 - Full Path Disclosure

medium

Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

CVSS:
5.3
Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
May 9, 2005

CVE-2005-1688 on NVD →

WordPress Core < 1.2.1 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameter...

CVSS:
6.1
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 6, 2004

CVE-2004-1559 on NVD →

WordPress Core <= 1.2 - HTTP Response Splitting

medium

CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.

CVSS:
5.3
Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Oct 6, 2004

CVE-2004-1584 on NVD →

WordPress Core < 0.72 - SQL Injection

high

SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

CVSS:
8.8
Affected:
up to 0.72
Fixed in:
0.72
Disclosed:
Oct 11, 2003

CVE-2003-1598 on NVD →

WordPress Core <= 0.70 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.

CVSS:
9.8
Affected:
up to 0.70
Fixed in:
0.71
Disclosed:
Jun 9, 2003

CVE-2003-1599 on NVD →

No data available

unknown
Fix:
No patched version reported

No data available

unknown
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database