WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 914
GHSA-chfm-w5r6-r24m
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
GHSA-h2pj-w259-mfcv
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
GHSA-mc26-rfqj-pwxf
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
GHSA-mwxx-w555-5h5m
WordPress before 5.5.2 allows stored XSS via post slugs.
GHSA-94cf-q7rf-65xg
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
GHSA-546f-q8mw-j4qj
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
GHSA-q684-cq3q-r3gp
WordPress before 5.5.2 allows XSS associated with global variables.
GHSA-vwhm-w9wm-r5pj
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
GHSA-8ggp-4pf2-5mgh
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
GHSA-8j68-mq56-8vpm
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-chfm-w5r6-r24m WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-h2pj-w259-mfcv is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation). | CVSS3: 9.8 | 8% Низкий | больше 4 лет назад | |
GHSA-mc26-rfqj-pwxf wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-mwxx-w555-5h5m WordPress before 5.5.2 allows stored XSS via post slugs. | CVSS3: 6.1 | 3% Низкий | больше 4 лет назад | |
GHSA-94cf-q7rf-65xg WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-546f-q8mw-j4qj WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | CVSS3: 9.8 | 16% Средний | больше 4 лет назад | |
GHSA-q684-cq3q-r3gp WordPress before 5.5.2 allows XSS associated with global variables. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-vwhm-w9wm-r5pj The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role. | 6% Низкий | больше 4 лет назад | ||
GHSA-8ggp-4pf2-5mgh In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | 2% Низкий | больше 4 лет назад | ||
GHSA-8j68-mq56-8vpm wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад |
Уязвимостей на страницу