WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 912
GHSA-chfm-w5r6-r24m
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
GHSA-mc26-rfqj-pwxf
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
GHSA-94cf-q7rf-65xg
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
GHSA-mwxx-w555-5h5m
WordPress before 5.5.2 allows stored XSS via post slugs.
GHSA-q684-cq3q-r3gp
WordPress before 5.5.2 allows XSS associated with global variables.
GHSA-546f-q8mw-j4qj
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
GHSA-vwhm-w9wm-r5pj
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
GHSA-8ggp-4pf2-5mgh
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
GHSA-8j68-mq56-8vpm
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
GHSA-ppxh-5qq2-77g8
WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-chfm-w5r6-r24m WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-mc26-rfqj-pwxf wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post. | CVSS3: 9.8 | 5% Низкий | около 4 лет назад | |
GHSA-94cf-q7rf-65xg WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | CVSS3: 9.8 | 4% Низкий | около 4 лет назад | |
GHSA-mwxx-w555-5h5m WordPress before 5.5.2 allows stored XSS via post slugs. | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-q684-cq3q-r3gp WordPress before 5.5.2 allows XSS associated with global variables. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-546f-q8mw-j4qj WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | CVSS3: 9.8 | 16% Средний | около 4 лет назад | |
GHSA-vwhm-w9wm-r5pj The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role. | 6% Низкий | около 4 лет назад | ||
GHSA-8ggp-4pf2-5mgh In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | 2% Низкий | около 4 лет назад | ||
GHSA-8j68-mq56-8vpm wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. | CVSS3: 9.8 | 5% Низкий | около 4 лет назад | |
GHSA-ppxh-5qq2-77g8 WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php. | CVSS3: 4.3 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу