Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5294

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5294

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5293

больше 11 лет назад

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2010-5293

больше 11 лет назад

wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ...

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться