Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

github логотип

GHSA-m8cv-g4gv-cx2g

больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

EPSS: Средний
github логотип

GHSA-65h5-8qpr-9m3v

больше 3 лет назад

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-86pg-877h-rfr2

больше 3 лет назад

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-chfm-w5r6-r24m

больше 3 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h2pj-w259-mfcv

больше 3 лет назад

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mc26-rfqj-pwxf

больше 3 лет назад

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-94cf-q7rf-65xg

больше 3 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mwxx-w555-5h5m

больше 3 лет назад

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-q684-cq3q-r3gp

больше 3 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-546f-q8mw-j4qj

больше 3 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-m8cv-g4gv-cx2g

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

25%
Средний
больше 3 лет назад
github логотип
GHSA-65h5-8qpr-9m3v

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS3: 9.1
5%
Низкий
больше 3 лет назад
github логотип
GHSA-86pg-877h-rfr2

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-chfm-w5r6-r24m

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-h2pj-w259-mfcv

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
9%
Низкий
больше 3 лет назад
github логотип
GHSA-mc26-rfqj-pwxf

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-94cf-q7rf-65xg

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-mwxx-w555-5h5m

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
16%
Средний
больше 3 лет назад
github логотип
GHSA-q684-cq3q-r3gp

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-546f-q8mw-j4qj

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
47%
Средний
больше 3 лет назад

Уязвимостей на страницу


Поделиться