Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.46.56.66.76.86.920232024202520262027

Недавние уязвимости WordPress

Количество 1 906

github логотип

GHSA-vwhm-w9wm-r5pj

больше 3 лет назад

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

EPSS: Средний
github логотип

GHSA-8ggp-4pf2-5mgh

больше 3 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

EPSS: Низкий
github логотип

GHSA-8j68-mq56-8vpm

больше 3 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgvp-37rp-x96c

больше 3 лет назад

WordPress before 5.3.1 allowed an attacker to create a cross-site scripting attack (XSS) in well crafted links, because of an insufficient protection mechanism in wp_targeted_link_rel in wp-includes/formatting.php.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-ppxh-5qq2-77g8

больше 3 лет назад

WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-93gm-xcwj-q3j2

больше 3 лет назад

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qhr7-69q6-5rp8

больше 3 лет назад

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rrjm-x5m6-q2pg

больше 3 лет назад

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-q76h-h683-9cc8

больше 3 лет назад

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-493w-chrv-wxpj

больше 3 лет назад

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vwhm-w9wm-r5pj

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

15%
Средний
больше 3 лет назад
github логотип
GHSA-8ggp-4pf2-5mgh

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-8j68-mq56-8vpm

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgvp-37rp-x96c

WordPress before 5.3.1 allowed an attacker to create a cross-site scripting attack (XSS) in well crafted links, because of an insufficient protection mechanism in wp_targeted_link_rel in wp-includes/formatting.php.

CVSS3: 6.1
19%
Средний
больше 3 лет назад
github логотип
GHSA-ppxh-5qq2-77g8

WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-93gm-xcwj-q3j2

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-qhr7-69q6-5rp8

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

CVSS3: 6.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-rrjm-x5m6-q2pg

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

CVSS3: 9.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-q76h-h683-9cc8

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVSS3: 5.3
79%
Высокий
больше 3 лет назад
github логотип
GHSA-493w-chrv-wxpj

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
5%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться