Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

github логотип

GHSA-h9mp-jg98-m7vh

больше 3 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

EPSS: Средний
github логотип

GHSA-h9g4-hjrv-3hqw

больше 3 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

EPSS: Средний
github логотип

GHSA-h8vf-v4qw-mvq4

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h62c-3j33-j9pq

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-h2q7-xm8h-x2gw

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-h2pj-w259-mfcv

около 3 лет назад

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-gv93-c8vm-3g8r

около 3 лет назад

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-grx2-xpgf-hf3r

около 3 лет назад

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-gqr2-x8f5-qhj4

больше 3 лет назад

SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

EPSS: Низкий
github логотип

GHSA-gq5c-r56r-pjjx

около 3 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

EPSS: Низкий
github логотип

GHSA-gpxx-3842-mjw3

больше 3 лет назад

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

EPSS: Низкий
github логотип

GHSA-gmjx-3rgm-r63g

около 3 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ggq7-6rpp-2v58

около 3 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

EPSS: Низкий
github логотип

GHSA-ggp3-c542-qp4x

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

EPSS: Низкий
github логотип

GHSA-gg7f-mrmc-j93p

больше 3 лет назад

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

EPSS: Средний
github логотип

GHSA-gcf4-g49h-9mp5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.

EPSS: Низкий
github логотип

GHSA-g94h-w5p9-mvxc

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-g734-67mf-ffrp

больше 3 лет назад

Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.

EPSS: Низкий
github логотип

GHSA-g5w2-qwqg-v4vf

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

EPSS: Низкий
github логотип

GHSA-g4q2-gc49-8q5w

около 3 лет назад

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h9mp-jg98-m7vh

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

23%
Средний
больше 3 лет назад
github логотип
GHSA-h9g4-hjrv-3hqw

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

64%
Средний
больше 3 лет назад
github логотип
GHSA-h8vf-v4qw-mvq4

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-h62c-3j33-j9pq

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-h2q7-xm8h-x2gw

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-h2pj-w259-mfcv

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVSS3: 9.8
13%
Средний
около 3 лет назад
github логотип
GHSA-gv93-c8vm-3g8r

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

CVSS3: 8.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-grx2-xpgf-hf3r

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

2%
Низкий
около 3 лет назад
github логотип
GHSA-gqr2-x8f5-qhj4

SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-gq5c-r56r-pjjx

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

1%
Низкий
около 3 лет назад
github логотип
GHSA-gpxx-3842-mjw3

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-gmjx-3rgm-r63g

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-ggq7-6rpp-2v58

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

3%
Низкий
около 3 лет назад
github логотип
GHSA-ggp3-c542-qp4x

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

3%
Низкий
около 3 лет назад
github логотип
GHSA-gg7f-mrmc-j93p

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

12%
Средний
больше 3 лет назад
github логотип
GHSA-gcf4-g49h-9mp5

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g94h-w5p9-mvxc

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-g734-67mf-ffrp

Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-g5w2-qwqg-v4vf

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

1%
Низкий
около 3 лет назад
github логотип
GHSA-g4q2-gc49-8q5w

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

CVSS3: 6.3
3%
Низкий
около 3 лет назад

Уязвимостей на страницу