WordPress
by WordPress
Source repositories
CVEs (371)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-9062 | Hig | 0.49 | 8.6 | 0.02 | May 18, 2017 | In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. | ||
| CVE-2017-5493 | Hig | 0.49 | 7.5 | 0.03 | Jan 15, 2017 | wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup. | ||
| CVE-2014-6412 | Hig | 0.46 | 8.1 | 0.05 | Apr 12, 2018 | WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach. | ||
| CVE-2024-4439 | Hig | 0.45 | 7.2 | 0.71 | May 3, 2024 | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and… | ||
| CVE-2021-39203 | Med | 0.44 | 6.8 | 0.01 | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain… | ||
| CVE-2017-5487 | Med | 0.44 | 5.3 | 0.87 | Jan 15, 2017 | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | ||
| CVE-2021-39201 | Hig | 0.43 | 7.6 | 0.01 | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions… | ||
| CVE-2017-14719 | Hig | 0.43 | 7.5 | 0.14 | Sep 23, 2017 | Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components. | ||
| CVE-2024-31111 | Med | 0.42 | 6.5 | 0.00 | Jun 25, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from… | ||
| CVE-2024-31210 | Hig | 0.42 | 7.6 | 0.01 | Apr 4, 2024 | WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for… | ||
| CVE-2023-38000 | Med | 0.42 | 6.5 | 0.01 | Oct 13, 2023 | Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions. | ||
| CVE-2011-1762 | Med | 0.42 | 6.5 | 0.01 | Apr 18, 2022 | A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission. | ||
| CVE-2019-17673 | Hig | 0.42 | 7.5 | 0.03 | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. | ||
| CVE-2018-20151 | Hig | 0.42 | 7.5 | 0.06 | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by… | ||
| CVE-2012-6707 | Hig | 0.42 | 7.5 | 0.01 | Oct 19, 2017 | WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as… | ||
| CVE-2017-14990 | Med | 0.42 | 6.5 | 0.02 | Oct 3, 2017 | WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access… | ||
| CVE-2017-14722 | Hig | 0.42 | 7.5 | 0.08 | Sep 23, 2017 | Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename. | ||
| CVE-2017-9065 | Hig | 0.42 | 7.5 | 0.04 | May 18, 2017 | In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. | ||
| CVE-2016-5839 | Hig | 0.42 | 7.5 | 0.03 | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors. | ||
| CVE-2016-5838 | Hig | 0.42 | 7.5 | 0.03 | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie. |
- risk 0.49cvss 8.6epss 0.02
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
- risk 0.49cvss 7.5epss 0.03
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
- risk 0.46cvss 8.1epss 0.05
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- risk 0.45cvss 7.2epss 0.71
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and…
- risk 0.44cvss 6.8epss 0.01
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain…
- risk 0.44cvss 5.3epss 0.87
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
- risk 0.43cvss 7.6epss 0.01
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions…
- risk 0.43cvss 7.5epss 0.14
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from…
- risk 0.42cvss 7.6epss 0.01
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for…
- risk 0.42cvss 6.5epss 0.01
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
- risk 0.42cvss 6.5epss 0.01
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
- risk 0.42cvss 7.5epss 0.03
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
- risk 0.42cvss 7.5epss 0.06
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by…
- risk 0.42cvss 7.5epss 0.01
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as…
- risk 0.42cvss 6.5epss 0.02
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access…
- risk 0.42cvss 7.5epss 0.08
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
- risk 0.42cvss 7.5epss 0.04
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
- risk 0.42cvss 7.5epss 0.03
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
- risk 0.42cvss 7.5epss 0.03
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
Page 3 of 19