VYPR

WordPress

by WordPress

Source repositories

CVEs (371)

  • CVE-2007-6013CriNov 19, 2007
    risk 0.57cvss 9.8epss 0.03

    Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

  • CVE-2022-21661HigJan 6, 2022
    risk 0.56cvss 8.0epss 0.98

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been…

  • CVE-2016-4029HigAug 7, 2016
    risk 0.56cvss 8.6epss 0.04

    WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

  • CVE-2021-44223HigNov 25, 2021
    risk 0.55cvss 8.1epss 0.29

    WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the…

  • CVE-2019-9787HigMar 14, 2019
    risk 0.54cvss 8.8epss 0.41

    WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed…

  • CVE-2019-8943MedFeb 20, 2019
    risk 0.53cvss 6.5epss 0.93

    WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the…

  • CVE-2016-6896HigJan 18, 2017
    risk 0.52cvss 7.1epss 0.38

    Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to…

  • CVE-2017-1000600HigSep 6, 2018
    risk 0.51cvss 8.8epss 0.04

    WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be…

  • CVE-2017-17091HigDec 2, 2017
    risk 0.51cvss 8.8epss 0.07

    wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

  • CVE-2017-1001000HigApr 3, 2017
    risk 0.51cvss 7.5epss 0.82

    The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts…

  • CVE-2022-21662HigJan 6, 2022
    risk 0.50cvss 8.0epss 0.65

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users.…

  • CVE-2020-11026HigApr 30, 2020
    risk 0.50cvss 8.7epss 0.02

    In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with…

  • CVE-2019-17675HigOct 17, 2019
    risk 0.50cvss 8.8epss 0.03

    WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

  • CVE-2017-9064HigMay 18, 2017
    risk 0.50cvss 8.8epss 0.02

    In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.

  • CVE-2017-5489HigJan 15, 2017
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

  • CVE-2016-2222HigMay 22, 2016
    risk 0.50cvss 8.6epss 0.08

    The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

  • CVE-2021-39202HigSep 9, 2021
    risk 0.49cvss 7.6epss 0.01

    WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to…

  • CVE-2021-29447HigApr 15, 2021
    risk 0.49cvss 7.1epss 0.86

    Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful…

  • CVE-2020-28033HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.03

    WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

  • CVE-2017-9066HigMay 18, 2017
    risk 0.49cvss 8.6epss 0.04

    In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

Page 2 of 19