Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

github логотип

GHSA-chfm-w5r6-r24m

около 4 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mc26-rfqj-pwxf

около 4 лет назад

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-94cf-q7rf-65xg

около 4 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mwxx-w555-5h5m

около 4 лет назад

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q684-cq3q-r3gp

около 4 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-546f-q8mw-j4qj

около 4 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-vwhm-w9wm-r5pj

около 4 лет назад

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

EPSS: Низкий
github логотип

GHSA-8ggp-4pf2-5mgh

около 4 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

EPSS: Низкий
github логотип

GHSA-8j68-mq56-8vpm

около 4 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-ppxh-5qq2-77g8

около 4 лет назад

WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-chfm-w5r6-r24m

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-mc26-rfqj-pwxf

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

CVSS3: 9.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-94cf-q7rf-65xg

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-mwxx-w555-5h5m

WordPress before 5.5.2 allows stored XSS via post slugs.

CVSS3: 6.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-q684-cq3q-r3gp

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-546f-q8mw-j4qj

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
16%
Средний
около 4 лет назад
github логотип
GHSA-vwhm-w9wm-r5pj

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

6%
Низкий
около 4 лет назад
github логотип
GHSA-8ggp-4pf2-5mgh

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

2%
Низкий
около 4 лет назад
github логотип
GHSA-8j68-mq56-8vpm

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-ppxh-5qq2-77g8

WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.

CVSS3: 4.3
2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться