Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

fstec логотип

BDU:2023-07524

больше 2 лет назад

Уязвимость функции qsm_remove_file_fd_question плагина The Quiz And Survey Master системы управления содержимым сайта WordPress, позволяющая нарушителю удалять произвольные файлы

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-pmh6-cq54-943m

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to caus ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mjj5-7gmf-mfjx

больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2022-3590

больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2022-3590

больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback ...

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2022-3590

больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-h8vf-v4qw-mvq4

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2023-07524

Уязвимость функции qsm_remove_file_fd_question плагина The Quiz And Survey Master системы управления содержимым сайта WordPress, позволяющая нарушителю удалять произвольные файлы

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-pmh6-cq54-943m

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 7.5
3%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
3%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to caus ...

CVSS3: 5.3
3%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
3%
Низкий
больше 2 лет назад
github логотип
GHSA-mjj5-7gmf-mfjx

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
21%
Средний
больше 2 лет назад
nvd логотип
CVE-2022-3590

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
21%
Средний
больше 2 лет назад
debian логотип
CVE-2022-3590

WordPress is affected by an unauthenticated blind SSRF in the pingback ...

CVSS3: 5.9
21%
Средний
больше 2 лет назад
ubuntu логотип
CVE-2022-3590

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
21%
Средний
больше 2 лет назад
github логотип
GHSA-h8vf-v4qw-mvq4

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.

CVSS3: 5.3
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться