VYPR

WordPress

by WordPress

Source repositories

CVEs (371)

  • CVE-2016-5837HigJun 29, 2016
    risk 0.42cvss 7.5epss 0.03

    WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

  • CVE-2016-5836HigJun 29, 2016
    risk 0.42cvss 7.5epss 0.04

    The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2016-5835HigJun 29, 2016
    risk 0.42cvss 7.5epss 0.04

    WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

  • CVE-2016-5832HigJun 29, 2016
    risk 0.42cvss 7.5epss 0.03

    The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

  • CVE-2022-21664HigJan 6, 2022
    risk 0.41cvss 7.4epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version…

  • CVE-2016-6897MedJan 18, 2017
    risk 0.41cvss 6.5epss 0.28

    Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to…

  • CVE-2016-2221HigMay 22, 2016
    risk 0.41cvss 7.4epss 0.04

    Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as…

  • CVE-2022-0220MedFeb 1, 2022
    risk 0.40cvss 6.1epss 0.02

    The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be…

  • CVE-2020-28038MedNov 2, 2020
    risk 0.40cvss 6.1epss 0.03

    WordPress before 5.5.2 allows stored XSS via post slugs.

  • CVE-2020-28034MedNov 2, 2020
    risk 0.40cvss 6.1epss 0.02

    WordPress before 5.5.2 allows XSS associated with global variables.

  • CVE-2018-1000556MedJun 26, 2018
    risk 0.40cvss 6.1epss 0.01

    WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be…

  • CVE-2017-5490MedJan 15, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to…

  • CVE-2017-5488MedJan 15, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

  • CVE-2016-6634MedAug 7, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2022-3590MedDec 14, 2022
    risk 0.39cvss 5.9epss 0.03

    WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

  • CVE-2023-2745MedMay 17, 2023
    risk 0.37cvss 5.4epss 0.80

    WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation…

  • CVE-2020-4047MedJun 12, 2020
    risk 0.37cvss 6.8epss 0.03

    In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is…

  • CVE-2020-11027MedApr 30, 2020
    risk 0.37cvss 6.1epss 0.14

    In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with…

  • CVE-2022-21663MedJan 6, 2022
    risk 0.36cvss 6.6epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in…

  • CVE-2018-20152MedDec 14, 2018
    risk 0.36cvss 6.5epss 0.04

    In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

Page 4 of 19