Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

nvd логотип

CVE-2011-5179

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-4422

почти 14 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4422

почти 14 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4421

почти 14 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-4421

почти 14 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-5106

почти 14 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2010-5106

почти 14 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-5106

почти 14 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4421

почти 14 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-4422

почти 14 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2011-5179

Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

CVSS2: 4.3
9%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
2%
Низкий
почти 14 лет назад

Уязвимостей на страницу


Поделиться