Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

ubuntu логотип

CVE-2022-43504

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8fxj-85rv-jj93

около 3 лет назад

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mv4-59rc-qvqm

около 3 лет назад

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j28g-8c73-vhw9

около 3 лет назад

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3rc6-mcgh-8jqq

около 3 лет назад

WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hqq8-34fg-q5jj

около 3 лет назад

WordPress before 5.2.3 allows XSS in shortcode previews.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-f824-fhqw-5fwj

около 3 лет назад

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v5hr-6h2c-gx45

около 3 лет назад

WordPress before 5.2.3 allows XSS in stored comments.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m8cv-g4gv-cx2g

около 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

EPSS: Средний
github логотип

GHSA-65h5-8qpr-9m3v

около 3 лет назад

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
2%
Низкий
больше 2 лет назад
github логотип
GHSA-8fxj-85rv-jj93

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-3mv4-59rc-qvqm

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVSS3: 5.4
5%
Низкий
около 3 лет назад
github логотип
GHSA-j28g-8c73-vhw9

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

CVSS3: 6.1
3%
Низкий
около 3 лет назад
github логотип
GHSA-3rc6-mcgh-8jqq

WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

CVSS3: 6.1
3%
Низкий
около 3 лет назад
github логотип
GHSA-hqq8-34fg-q5jj

WordPress before 5.2.3 allows XSS in shortcode previews.

CVSS3: 6.1
4%
Низкий
около 3 лет назад
github логотип
GHSA-f824-fhqw-5fwj

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-v5hr-6h2c-gx45

WordPress before 5.2.3 allows XSS in stored comments.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-m8cv-g4gv-cx2g

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

40%
Средний
около 3 лет назад
github логотип
GHSA-65h5-8qpr-9m3v

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS3: 9.1
6%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться