Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

ubuntu логотип

CVE-2012-4422

больше 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4422

больше 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4422

больше 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4421

больше 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4421

больше 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-4421

больше 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-3385

больше 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3385

больше 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3385

больше 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3384

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3384

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-3384

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-3383

больше 13 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-3383

больше 13 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-3383

больше 13 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-2404

почти 14 лет назад

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2404

почти 14 лет назад

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-2404

почти 14 лет назад

wp-comments-post.php in WordPress before 3.3.2 supports offsite redire ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-2403

почти 14 лет назад

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2403

почти 14 лет назад

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2404

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-2404

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-2404

wp-comments-post.php in WordPress before 3.3.2 supports offsite redire ...

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-2403

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
3%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-2403

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
3%
Низкий
почти 14 лет назад

Уязвимостей на страницу