WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 906
GHSA-vwhm-w9wm-r5pj
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
GHSA-8ggp-4pf2-5mgh
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
GHSA-8j68-mq56-8vpm
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
GHSA-xgvp-37rp-x96c
WordPress before 5.3.1 allowed an attacker to create a cross-site scripting attack (XSS) in well crafted links, because of an insufficient protection mechanism in wp_targeted_link_rel in wp-includes/formatting.php.
GHSA-ppxh-5qq2-77g8
WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.
GHSA-93gm-xcwj-q3j2
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
GHSA-qhr7-69q6-5rp8
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
GHSA-rrjm-x5m6-q2pg
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
GHSA-q76h-h683-9cc8
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
GHSA-493w-chrv-wxpj
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-vwhm-w9wm-r5pj The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role. | 15% Средний | больше 3 лет назад | ||
GHSA-8ggp-4pf2-5mgh In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | 1% Низкий | больше 3 лет назад | ||
GHSA-8j68-mq56-8vpm wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xgvp-37rp-x96c WordPress before 5.3.1 allowed an attacker to create a cross-site scripting attack (XSS) in well crafted links, because of an insufficient protection mechanism in wp_targeted_link_rel in wp-includes/formatting.php. | CVSS3: 6.1 | 19% Средний | больше 3 лет назад | |
GHSA-ppxh-5qq2-77g8 WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-93gm-xcwj-q3j2 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
GHSA-qhr7-69q6-5rp8 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | CVSS3: 6.1 | 4% Низкий | больше 3 лет назад | |
GHSA-rrjm-x5m6-q2pg WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 8% Низкий | больше 3 лет назад | |
GHSA-q76h-h683-9cc8 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | CVSS3: 5.3 | 79% Высокий | больше 3 лет назад | |
GHSA-493w-chrv-wxpj WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. | CVSS3: 8.8 | 5% Низкий | больше 3 лет назад |
Уязвимостей на страницу