WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 912
GHSA-w8h5-qp6m-vfm9
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
GHSA-33wf-jvrq-cxjv
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.
GHSA-f844-ppv9-vxhv
In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
GHSA-jgj7-cghf-2wq9
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
GHSA-4mq7-pxfh-pjjv
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
GHSA-j4jj-c644-q3fc
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
GHSA-ccmp-622j-3xf7
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
GHSA-hmqr-j9c3-8h75
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
GHSA-6f4p-6vw9-3q54
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
GHSA-8chx-6qqw-75xx
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-w8h5-qp6m-vfm9 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. | CVSS3: 5.4 | 2% Низкий | около 4 лет назад | |
GHSA-33wf-jvrq-cxjv In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data. | CVSS3: 5.4 | 3% Низкий | около 4 лет назад | |
GHSA-f844-ppv9-vxhv In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. | CVSS3: 6.1 | 5% Низкий | около 4 лет назад | |
GHSA-jgj7-cghf-2wq9 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php. | CVSS3: 9.8 | 30% Средний | около 4 лет назад | |
GHSA-4mq7-pxfh-pjjv In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default. | CVSS3: 7.5 | 7% Низкий | около 4 лет назад | |
GHSA-j4jj-c644-q3fc In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. | CVSS3: 6.5 | 4% Низкий | около 4 лет назад | |
GHSA-ccmp-622j-3xf7 Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server. | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-hmqr-j9c3-8h75 In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. | CVSS3: 8.6 | 4% Низкий | около 4 лет назад | |
GHSA-6f4p-6vw9-3q54 In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. | CVSS3: 7.5 | 4% Низкий | около 4 лет назад | |
GHSA-8chx-6qqw-75xx In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу