Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

debian логотип

CVE-2012-3385

около 14 лет назад

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-3385

около 14 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-4033

около 14 лет назад

Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2012-3814

около 14 лет назад

Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
3%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-4033

Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors.

CVSS2: 10
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3814

Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.

CVSS2: 7.5
10%
Средний
около 14 лет назад

Уязвимостей на страницу


Поделиться