VYPR

WordPress

by WordPress

Source repositories

CVEs (371)

  • CVE-2026-63030CriKEVJul 17, 2026
    risk 0.84cvss 9.8epss 0.96

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

  • CVE-2016-10033CriKEVDec 30, 2016
    risk 0.80cvss 9.8epss 1.00

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

  • CVE-2016-10045CriDec 30, 2016
    risk 0.68cvss 9.8epss 0.98

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail…

  • CVE-2020-28035CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.04

    WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

  • CVE-2019-8942HigFeb 20, 2019
    risk 0.60cvss 8.8epss 0.83

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by…

  • CVE-2018-20148CriDec 14, 2018
    risk 0.59cvss 9.8epss 0.27

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in…

  • CVE-2026-64638HigAug 7, 2026
    risk 0.58cvss epss 0.01

    WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers…

  • CVE-2018-1000773HigSep 6, 2018
    risk 0.58cvss 8.8epss 0.08

    WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated…

  • CVE-2018-12895HigJun 26, 2018
    risk 0.58cvss 8.8epss 0.63

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in…

  • CVE-2018-6389HigFeb 6, 2018
    risk 0.58cvss 7.5epss 0.73

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

  • CVE-2017-14723CriSep 23, 2017
    risk 0.58cvss 9.8epss 0.07

    Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

  • CVE-2026-60137MedKEVJul 17, 2026
    risk 0.57cvss 5.9epss 0.73

    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

  • CVE-2020-36326CriApr 28, 2021
    risk 0.57cvss 9.8epss 0.03

    PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by…

  • CVE-2019-17670CriOct 17, 2019
    risk 0.57cvss 9.8epss 0.05

    WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

  • CVE-2019-17669CriOct 17, 2019
    risk 0.57cvss 9.8epss 0.05

    WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

  • CVE-2018-19296HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.02

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

  • CVE-2017-16510CriNov 2, 2017
    risk 0.57cvss 9.8epss 0.07

    WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

  • CVE-2017-5611CriJan 30, 2017
    risk 0.57cvss 9.8epss 0.10

    SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

  • CVE-2017-5492HigJan 15, 2017
    risk 0.57cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to…

  • CVE-2016-6635HigAug 7, 2016
    risk 0.57cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

Page 1 of 19