VYPR

WordPress

by WordPress

Source repositories

CVEs (374)

  • CVE-2020-4048MedJun 12, 2020
    risk 0.30cvss 5.7epss 0.02

    In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions…

  • CVE-2024-31211MedApr 4, 2024
    risk 0.29cvss 5.5epss 0.03

    WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

  • CVE-2023-5561MedOct 16, 2023
    risk 0.28cvss 5.3epss 0.04

    WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

  • CVE-2022-43504MedDec 5, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all…

  • CVE-2021-39200MedSep 9, 2021
    risk 0.28cvss 5.3epss 0.02

    WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to…

  • CVE-2020-28040MedNov 2, 2020
    risk 0.28cvss 4.3epss 0.01

    WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

  • CVE-2020-4046MedJun 12, 2020
    risk 0.28cvss 5.4epss 0.02

    In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in…

  • CVE-2019-17674MedOct 17, 2019
    risk 0.28cvss 5.4epss 0.02

    WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

  • CVE-2018-20153MedDec 14, 2018
    risk 0.28cvss 5.4epss 0.03

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

  • CVE-2018-20149MedDec 14, 2018
    risk 0.28cvss 5.4epss 0.04

    In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

  • CVE-2017-17094MedDec 2, 2017
    risk 0.28cvss 5.4epss 0.03

    wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

  • CVE-2017-17093MedDec 2, 2017
    risk 0.28cvss 5.4epss 0.03

    wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

  • CVE-2017-17092MedDec 2, 2017
    risk 0.28cvss 5.4epss 0.06

    wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

  • CVE-2017-14725MedSep 23, 2017
    risk 0.28cvss 5.4epss 0.03

    Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

  • CVE-2017-6817MedMar 12, 2017
    risk 0.28cvss 5.4epss 0.03

    In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.

  • CVE-2017-6814MedMar 12, 2017
    risk 0.28cvss 5.4epss 0.04

    In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in…

  • CVE-2017-5610MedJan 30, 2017
    risk 0.28cvss 5.3epss 0.06

    wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

  • CVE-2015-7989MedMay 22, 2016
    risk 0.28cvss 5.4epss 0.03

    Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.

  • CVE-2017-6816MedMar 12, 2017
    risk 0.25cvss 4.9epss 0.04

    In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.

  • CVE-2016-9263MedOct 12, 2017
    risk 0.24cvss 4.7epss 0.03

    WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

Page 8 of 19