Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

nvd логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
EPSS: Критический
debian логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An a ...

CVSS3: 6.5
EPSS: Критический
nvd логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
EPSS: Высокий
debian логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code executi ...

CVSS3: 8.8
EPSS: Высокий
ubuntu логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
EPSS: Высокий
ubuntu логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
EPSS: Критический
nvd логотип

CVE-2018-20153

больше 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-20153

больше 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-20152

больше 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-20152

больше 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
93%
Критический
больше 7 лет назад
debian логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An a ...

CVSS3: 6.5
93%
Критический
больше 7 лет назад
nvd логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
debian логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code executi ...

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
ubuntu логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
ubuntu логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
93%
Критический
больше 7 лет назад
nvd логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
4%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
4%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться