Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2013-5961

почти 12 лет назад

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4626

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5918

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5917

почти 12 лет назад

SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-5739

около 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-5739

около 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-5738

около 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5738

около 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4340

около 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4340

около 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-5961

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

CVSS2: 6.8
8%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-4626

Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5918

Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5917

SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
1%
Низкий
около 12 лет назад

Уязвимостей на страницу


Поделиться