Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

ubuntu логотип

CVE-2023-5561

почти 2 года назад

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2023-5561

почти 2 года назад

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2023-5561

почти 2 года назад

WordPress does not properly restrict which user fields are searchable ...

CVSS3: 5.3
EPSS: Средний
ubuntu логотип

CVE-2023-39999

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-39999

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-39999

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor in WordPres ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-2745

около 2 лет назад

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVSS3: 5.4
EPSS: Средний
nvd логотип

CVE-2023-2745

около 2 лет назад

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2023-2745

около 2 лет назад

WordPress Core is vulnerable to Directory Traversal in versions up to, ...

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-22622

больше 2 лет назад

WordPress through 6.1.1 depends on unpredictable client visits to caus ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-4973

10 месяцев назад

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2022-4973

10 месяцев назад

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2022-4973

10 месяцев назад

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticate ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2022-43504

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-43504

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-43504

больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-43500

больше 2 лет назад

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-43500

больше 2 лет назад

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
60%
Средний
почти 2 года назад
nvd логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
60%
Средний
почти 2 года назад
debian логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable ...

CVSS3: 5.3
60%
Средний
почти 2 года назад
ubuntu логотип
CVE-2023-39999

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-39999

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
debian логотип
CVE-2023-39999

Exposure of Sensitive Information to an Unauthorized Actor in WordPres ...

CVSS3: 4.3
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-2745

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVSS3: 5.4
69%
Средний
около 2 лет назад
nvd логотип
CVE-2023-2745

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVSS3: 5.4
69%
Средний
около 2 лет назад
debian логотип
CVE-2023-2745

WordPress Core is vulnerable to Directory Traversal in versions up to, ...

CVSS3: 5.4
69%
Средний
около 2 лет назад
ubuntu логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
4%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

CVSS3: 5.3
4%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to caus ...

CVSS3: 5.3
4%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-4973

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2022-4973

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
debian логотип
CVE-2022-4973

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticate ...

CVSS3: 4.9
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6 ...

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-43500

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-43500

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу