Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

github логотип

GHSA-93gm-xcwj-q3j2

около 3 лет назад

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9354-f967-7fw8

больше 3 лет назад

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

EPSS: Низкий
github логотип

GHSA-92h3-fjv6-rmmc

около 3 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-928v-37ff-2cvr

около 3 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8xjm-q43j-6v96

около 3 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

EPSS: Низкий
github логотип

GHSA-8wqr-ch99-7r8g

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

EPSS: Низкий
github логотип

GHSA-8rwr-ffp6-2577

около 3 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

EPSS: Низкий
github логотип

GHSA-8rr8-9498-4v45

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

EPSS: Низкий
github логотип

GHSA-8rmg-wmq4-q93v

около 3 лет назад

Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-8p43-h625-cvh5

около 3 лет назад

Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-8j68-mq56-8vpm

около 3 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8ggp-4pf2-5mgh

около 3 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

EPSS: Низкий
github логотип

GHSA-8fxj-85rv-jj93

около 3 лет назад

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8chx-6qqw-75xx

около 3 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8cg5-rjxh-5v62

около 3 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

EPSS: Низкий
github логотип

GHSA-8c9g-j366-5fcx

около 3 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-893q-vmc7-qcvh

около 3 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-86pg-877h-rfr2

около 3 лет назад

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8688-jv8f-2mcf

около 3 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8292-xqwp-qw46

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-93gm-xcwj-q3j2

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS3: 7.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-9354-f967-7fw8

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-92h3-fjv6-rmmc

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
29%
Средний
около 3 лет назад
github логотип
GHSA-928v-37ff-2cvr

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
5%
Низкий
около 3 лет назад
github логотип
GHSA-8xjm-q43j-6v96

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

1%
Низкий
около 3 лет назад
github логотип
GHSA-8wqr-ch99-7r8g

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-8rwr-ffp6-2577

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

2%
Низкий
около 3 лет назад
github логотип
GHSA-8rr8-9498-4v45

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

1%
Низкий
около 3 лет назад
github логотип
GHSA-8rmg-wmq4-q93v

Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

CVSS3: 7.5
48%
Средний
около 3 лет назад
github логотип
GHSA-8p43-h625-cvh5

Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

2%
Низкий
около 3 лет назад
github логотип
GHSA-8j68-mq56-8vpm

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-8ggp-4pf2-5mgh

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

0%
Низкий
около 3 лет назад
github логотип
GHSA-8fxj-85rv-jj93

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-8chx-6qqw-75xx

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-8cg5-rjxh-5v62

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

0%
Низкий
около 3 лет назад
github логотип
GHSA-8c9g-j366-5fcx

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-893q-vmc7-qcvh

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-86pg-877h-rfr2

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-8688-jv8f-2mcf

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-8292-xqwp-qw46

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.

4%
Низкий
больше 3 лет назад

Уязвимостей на страницу