VYPR

WordPress

by WordPress

Source repositories

CVEs (374)

  • CVE-2026-63030CriKEVJul 17, 2026
    risk 0.84cvss 9.8epss 0.10

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

  • CVE-2016-10033CriKEVDec 30, 2016
    risk 0.80cvss 9.8epss 1.00

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

  • CVE-2016-10045CriDec 30, 2016
    risk 0.68cvss 9.8epss 0.98

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail…

  • CVE-2026-87902HigKEVSep 22, 2026
    risk 0.66cvss 8.1epss 0.22

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

  • CVE-2020-28032CriNov 2, 2020
    risk 0.65cvss 9.8epss 0.16

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

  • CVE-2020-28037CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.08

    is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old…

  • CVE-2020-28036CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.05

    wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

  • CVE-2020-28035CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.04

    WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

  • CVE-2019-20041CriDec 27, 2019
    risk 0.64cvss 9.8epss 0.05

    wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

  • CVE-2026-64638HigAug 7, 2026
    risk 0.60cvss —epss 0.01

    WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers…

  • CVE-2019-8942HigFeb 20, 2019
    risk 0.60cvss 8.8epss 0.83

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by…

  • CVE-2020-28039CriNov 2, 2020
    risk 0.59cvss 9.1epss 0.04

    is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

  • CVE-2018-20148CriDec 14, 2018
    risk 0.59cvss 9.8epss 0.27

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in…

  • CVE-2018-1000773HigSep 6, 2018
    risk 0.58cvss 8.8epss 0.08

    WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated…

  • CVE-2018-12895HigJun 26, 2018
    risk 0.58cvss 8.8epss 0.62

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in…

  • CVE-2018-6389HigFeb 6, 2018
    risk 0.58cvss 7.5epss 0.73

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

  • CVE-2026-65640HigAug 17, 2026
    risk 0.57cvss 8.8epss 0.01

    WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all…

  • CVE-2026-60137MedKEVJul 17, 2026
    risk 0.57cvss 5.9epss 0.06

    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

  • CVE-2020-36326CriApr 28, 2021
    risk 0.57cvss 9.8epss 0.03

    PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by…

  • CVE-2019-17670CriOct 17, 2019
    risk 0.57cvss 9.8epss 0.05

    WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

Page 1 of 19