Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

github логотип

GHSA-w8h5-qp6m-vfm9

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33wf-jvrq-cxjv

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-f844-ppv9-vxhv

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jgj7-cghf-2wq9

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4mq7-pxfh-pjjv

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j4jj-c644-q3fc

около 4 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ccmp-622j-3xf7

около 4 лет назад

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hmqr-j9c3-8h75

около 4 лет назад

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-6f4p-6vw9-3q54

около 4 лет назад

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8chx-6qqw-75xx

около 4 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-w8h5-qp6m-vfm9

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-33wf-jvrq-cxjv

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
3%
Низкий
около 4 лет назад
github логотип
GHSA-f844-ppv9-vxhv

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
5%
Низкий
около 4 лет назад
github логотип
GHSA-jgj7-cghf-2wq9

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

CVSS3: 9.8
30%
Средний
около 4 лет назад
github логотип
GHSA-4mq7-pxfh-pjjv

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
7%
Низкий
около 4 лет назад
github логотип
GHSA-j4jj-c644-q3fc

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-ccmp-622j-3xf7

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

CVSS3: 6.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-hmqr-j9c3-8h75

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS3: 8.6
4%
Низкий
около 4 лет назад
github логотип
GHSA-6f4p-6vw9-3q54

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-8chx-6qqw-75xx

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться