Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

debian логотип

CVE-2020-25286

почти 5 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comment ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-25286

почти 5 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-4050

около 5 лет назад

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2020-4050

около 5 лет назад

In affected versions of WordPress, misuse of the `set-screen-option` f ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2020-4049

около 5 лет назад

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 2.4
EPSS: Низкий
debian логотип

CVE-2020-4049

около 5 лет назад

In affected versions of WordPress, when uploading themes, the name of ...

CVSS3: 2.4
EPSS: Низкий
nvd логотип

CVE-2020-4048

около 5 лет назад

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2020-4048

около 5 лет назад

In affected versions of WordPress, due to an issue in wp_validate_redi ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2020-4047

около 5 лет назад

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2020-4047

около 5 лет назад

In affected versions of WordPress, authenticated users with upload per ...

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comment ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-4050

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 3.5
2%
Низкий
около 5 лет назад
debian логотип
CVE-2020-4050

In affected versions of WordPress, misuse of the `set-screen-option` f ...

CVSS3: 3.5
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-4049

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 2.4
2%
Низкий
около 5 лет назад
debian логотип
CVE-2020-4049

In affected versions of WordPress, when uploading themes, the name of ...

CVSS3: 2.4
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-4048

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 5.7
3%
Низкий
около 5 лет назад
debian логотип
CVE-2020-4048

In affected versions of WordPress, due to an issue in wp_validate_redi ...

CVSS3: 5.7
3%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-4047

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

CVSS3: 6.8
3%
Низкий
около 5 лет назад
debian логотип
CVE-2020-4047

In affected versions of WordPress, authenticated users with upload per ...

CVSS3: 6.8
3%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться