VYPR

WordPress

by WordPress

Source repositories

CVEs (371)

  • CVE-2018-20147MedDec 14, 2018
    risk 0.36cvss 6.5epss 0.03

    In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

  • CVE-2017-8295MedMay 4, 2017
    risk 0.36cvss 5.9epss 0.27

    WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be…

  • CVE-2025-5092MedNov 20, 2025
    risk 0.35cvss 6.4epss 0.00

    Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

  • CVE-2025-11154MedOct 27, 2025
    risk 0.35cvss 5.4epss 0.00

    The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

  • CVE-2023-22622MedJan 5, 2023
    risk 0.35cvss 5.3epss 0.02

    WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither…

  • CVE-2021-29450MedApr 15, 2021
    risk 0.35cvss 6.5epss 0.02

    Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions…

  • CVE-2020-25286MedSep 13, 2020
    risk 0.35cvss 5.3epss 0.02

    In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

  • CVE-2020-11030MedApr 30, 2020
    risk 0.35cvss 6.4epss 0.01

    In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all…

  • CVE-2017-6514MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.03

    WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

  • CVE-2017-6819MedMar 12, 2017
    risk 0.35cvss 6.5epss 0.02

    In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.

  • CVE-2017-5491MedJan 15, 2017
    risk 0.35cvss 5.3epss 0.03

    wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

  • CVE-2006-6017MedNov 21, 2006
    risk 0.35cvss 6.5epss 0.02

    WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized…

  • CVE-2006-6016MedNov 21, 2006
    risk 0.35cvss 6.5epss 0.02

    wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.

  • CVE-2005-1688MedMay 20, 2005
    risk 0.35cvss 5.3epss 0.02

    Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

  • CVE-2016-7169MedJan 5, 2017
    risk 0.34cvss 6.3epss 0.03

    Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

  • CVE-2024-32111MedJun 25, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from…

  • CVE-2022-43500MedDec 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

  • CVE-2022-43497MedDec 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

  • CVE-2019-17672MedOct 17, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

  • CVE-2019-17671MedOct 17, 2019
    risk 0.33cvss 5.3epss 0.36

    In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

Page 5 of 19