WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 896
GHSA-m8cv-g4gv-cx2g
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
GHSA-65h5-8qpr-9m3v
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
GHSA-86pg-877h-rfr2
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
GHSA-chfm-w5r6-r24m
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
GHSA-h2pj-w259-mfcv
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
GHSA-mc26-rfqj-pwxf
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
GHSA-94cf-q7rf-65xg
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
GHSA-mwxx-w555-5h5m
WordPress before 5.5.2 allows stored XSS via post slugs.
GHSA-q684-cq3q-r3gp
WordPress before 5.5.2 allows XSS associated with global variables.
GHSA-546f-q8mw-j4qj
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано 1  | |
|---|---|---|---|---|
GHSA-m8cv-g4gv-cx2g WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.  | 25% Средний | больше 3 лет назад | ||
GHSA-65h5-8qpr-9m3v is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.  | CVSS3: 9.1  | 5% Низкий | больше 3 лет назад | |
GHSA-86pg-877h-rfr2 WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.  | CVSS3: 4.3  | 0% Низкий | больше 3 лет назад | |
GHSA-chfm-w5r6-r24m WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.  | CVSS3: 7.5  | 2% Низкий | больше 3 лет назад | |
GHSA-h2pj-w259-mfcv is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).  | CVSS3: 9.8  | 9% Низкий | больше 3 лет назад | |
GHSA-mc26-rfqj-pwxf wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.  | CVSS3: 9.8  | 2% Низкий | больше 3 лет назад | |
GHSA-94cf-q7rf-65xg WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.  | CVSS3: 9.8  | 3% Низкий | больше 3 лет назад | |
GHSA-mwxx-w555-5h5m WordPress before 5.5.2 allows stored XSS via post slugs.  | CVSS3: 6.1  | 16% Средний | больше 3 лет назад | |
GHSA-q684-cq3q-r3gp WordPress before 5.5.2 allows XSS associated with global variables.  | CVSS3: 6.1  | 3% Низкий | больше 3 лет назад | |
GHSA-546f-q8mw-j4qj WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.  | CVSS3: 9.8  | 47% Средний | больше 3 лет назад | 
Уязвимостей на страницу