Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

github логотип

GHSA-86pg-877h-rfr2

около 3 лет назад

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h2pj-w259-mfcv

около 3 лет назад

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-chfm-w5r6-r24m

около 3 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mwxx-w555-5h5m

около 3 лет назад

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-mc26-rfqj-pwxf

около 3 лет назад

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-94cf-q7rf-65xg

около 3 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-546f-q8mw-j4qj

около 3 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-q684-cq3q-r3gp

около 3 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vwhm-w9wm-r5pj

около 3 лет назад

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

EPSS: Средний
github логотип

GHSA-8ggp-4pf2-5mgh

около 3 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-86pg-877h-rfr2

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-h2pj-w259-mfcv

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
13%
Средний
около 3 лет назад
github логотип
GHSA-chfm-w5r6-r24m

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-mwxx-w555-5h5m

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
16%
Средний
около 3 лет назад
github логотип
GHSA-mc26-rfqj-pwxf

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-94cf-q7rf-65xg

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-546f-q8mw-j4qj

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
21%
Средний
около 3 лет назад
github логотип
GHSA-q684-cq3q-r3gp

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
3%
Низкий
около 3 лет назад
github логотип
GHSA-vwhm-w9wm-r5pj

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

17%
Средний
около 3 лет назад
github логотип
GHSA-8ggp-4pf2-5mgh

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться